PT-2023-28290 · Yeelight+5 · Yeelight Smart Lamp+5

Agatha2333

·

Publicado

2023-10-10

·

Atualizado

2024-02-15

·

CVE-2023-42189

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Connectivity Standards Alliance Matter Official SDK version 1.1.0.0 Nanoleaf Light strip version 3.5.10 Govee LED Strip version 3.00.42 switchBot Hub2 versions 1.0-0.8 Phillips hue hub version 1.59.1959097030 yeelight smart lamp version 1.12.69
Description The issue allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function. This can lead to service disruption.
Recommendations For Connectivity Standards Alliance Matter Official SDK version 1.1.0.0, consider disabling the KeySetRemove function until a patch is available. For Nanoleaf Light strip version 3.5.10, restrict access to the KeySetRemove function to minimize the risk of exploitation. For Govee LED Strip version 3.00.42, avoid using the KeySetRemove function in scripts until the issue is resolved. For switchBot Hub2 versions 1.0-0.8, apply configuration changes to limit the impact of the denial of service. For Phillips hue hub version 1.59.1959097030, consider implementing additional security measures to prevent crafted scripts from reaching the KeySetRemove function. For yeelight smart lamp version 1.12.69, temporarily disable the KeySetRemove function to prevent potential attacks.

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-42189

Produtos afetados

Connectivity Standards Alliance Matter Official Sdk
Govee Led Strip
Nanoleaf Light Strip
Phillips Hue Hub
Switchbot Hub2
Yeelight Smart Lamp