CVE-2023-4617
CVE-2023-4617
Título es
CVE-2023-4617
Jue, 19/12/2024 – 10:15
Tipo
CWE-863
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2023-4617
Descripción en
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.
This issue affects Govee Home applications on Android and iOS in versions before 5.9.
This issue affects Govee Home applications on Android and iOS in versions before 5.9.
19/12/2024
19/12/2024
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
Gravedad 3.1 (CVSS 3.1 Base Score)
10.00
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
CRITICAL
Referencias
Enviar en el boletín
Off
