Логотип exploitDog
bind:CVE-2023-4617
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-4617

Количество 2

Количество 2

nvd логотип

CVE-2023-4617

около 1 года назад

Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-59pp-rvhc-93rh

около 1 года назад

Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-4617

Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.

CVSS3: 10
2%
Низкий
около 1 года назад
github логотип
GHSA-59pp-rvhc-93rh

Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.

CVSS3: 10
2%
Низкий
около 1 года назад

Уязвимостей на страницу