Back to overview

CVE-2023-4617

CRITICAL
10.0
CVSS 3.1
Description
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.

Metadata

CVE ID
CVE-2023-4617
State
PUBLISHED
Assigner
CERT-PL
Reserved
2023-08-30 08:30 UTC
Published
2024-12-19 09:39 UTC
Last updated
2024-12-20 17:56 UTC
Primary CWE
CWE-863
CWE-863 Incorrect Authorization
Vendor / Product
Govee / Govee Home
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (2)
VendorProductPlatformVersions
Govee Govee Home Android 0 < 5.9
Govee Govee Home iOS 0 < 5.9
Weakness (CWE)
CWESourceDescription
CWE-863 cna CWE-863 Incorrect Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
Back to overview