CVE-2023-4617
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" an...
Affects 0 products across 2 vendors.
Software performs an authorization check incorrectly, allowing access beyond intended privileges.
A critical authorization flaw in the Govee Home application for Android and iOS allows remote attackers to control devices belonging to other users by manipulating specific fields in HTTP POST requests.
BSID: BS-2024-GLOBAL-024819-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2023-4617?
What is the CVSS score for CVE-2023-4617?
Is CVE-2023-4617 actively exploited?
How do I remediate CVE-2023-4617?
What systems are affected by CVE-2023-4617?
| CVE ID | CVE-2023-4617 |
|---|---|
| BSID | BS-2024-GLOBAL-024819-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H |
| Published | 2024-12-19 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Source | NVD |
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values. This issue affects Govee Home applications on Android and iOS in versions before 5.9.
Source: NIST NVD / MITRE CVE Database
The vulnerability exists in the HTTP POST method handling within the Govee Home application. An attacker can exploit this by sending malicious requests with altered 'device', 'sku', and 'type' fields to control unauthorized devices.
Exploitation Likelihood: CRITICAL
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 7042ba4c10978c7de20049f128e3b7f133645d3f1139d01b344d0c12838e337b5f7feba8278f72a6e47b277209c3989438154dfe185157e0bd59309e2503d183 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →