Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-4617

Опубликовано: 19 дек. 2024
Источник: nvd
CVSS3: 10
EPSS Низкий

Описание

Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.

EPSS

Процентиль: 81%
0.01523
Низкий

10 Critical

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 10
github
около 1 года назад

Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.

EPSS

Процентиль: 81%
0.01523
Низкий

10 Critical

CVSS3

Дефекты

CWE-863