CVE ID | CVE-2023-4617 |
Publication date | 19 December 2024 |
Vendor | Govee |
Product | Govee Home |
Vulnerable versions | All before 5.9 |
Vulnerability type (CWE) | Incorrect Authorization (CWE-863) |
Report source | NASK own research |
Description
CERT Polska has received a report about vulnerability in Govee Home software and participated in coordination of its disclosure.
Incorrect authorization vulnerability CVE-2023-4617 in HTTP POST method allows a remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values. This issue affects Govee Home applications on Android and iOS in versions before 5.9.
Credits
We thank Jan Adamski and Marek Janiszewski from NASK for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.