CVE-2023-4617
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Dec 19, 2024
CWE ID 204
Summary
CVE-2023-4617 is an authorization vulnerability affecting the Govee Home application on both Android and iOS platforms. An attacker can exploit this issue by manipulating the "device," "sku," and "type" fields during HTTP POST requests, enabling unauthorized control over other users' devices. The vulnerability is present in versions of the application prior to 5.9, posing a significant security risk to affected users.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.