CVE-2023-4617

Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.
Configurations

No configuration.

History

19 Dec 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-19 10:15

Updated : 2024-12-19 10:15


NVD link : CVE-2023-4617

Mitre link : CVE-2023-4617

CVE.ORG link : CVE-2023-4617


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization