CVE-2023-3612
Last modified
CVE-2023-3612 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Govee | Home | < 5.8.01 |
References
- https://www.sk-cert.sk/threat/sk-cert-bezpecnostne-varovanie-v20230811-10Third Party Advisory
- https://www.sk-cert.sk/threat/sk-cert-bezpecnostne-varovanie-v20230811-10Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3612?
How severe is CVE-2023-3612?
How do I fix CVE-2023-3612?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-36103Command Injection vulnerability in goform/SetIPTVCfg interfa…9.8
- CVE-2023-36106An incorrect access control vulnerability in powerjob 4.3.2 …7.5
- CVE-2023-36109Buffer Overflow vulnerability in JerryScript version 3.0, al…9.8
- CVE-2023-3611An out-of-bounds write vulnerability in the Linux kernel's n…7.8
- CVE-2023-36118Cross Site Scripting vulnerability in Faculty Evaulation Sys…5.4
- CVE-2023-36119Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: non…
- CVE-2023-36120Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: non…
- CVE-2023-36121Cross Site Scripting vulnerability in e107 v.2.3.2 allows a …5.4
- CVE-2023-36123Directory Traversal vulnerability in Hex-Dragon Plain Craft …7.8
- CVE-2023-36126There is a Cross Site Scripting (XSS) vulnerability in the "…6.1
- CVE-2023-36127User enumeration is found in in PHPJabbers Appointment Sched…7.5
- CVE-2023-3613Mattermost WelcomeBot plugin fails to to validate the member…3.5
Are you affected by CVE-2023-3612?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
