Information Disclosure in Nest Cam IQ Indoor by Google
CVE-2019-5034

5.3MEDIUM

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
20 August 2019

Summary

An information disclosure vulnerability has been identified within the legacy pairing functionality of Nest Cam IQ Indoor version 4620002. Through the use of specially crafted weave packets, an attacker can exploit this vulnerability, leading to an out-of-bounds read scenario. This exploitation may allow sensitive information to be disclosed, enabling malicious actors to gain unauthorized access to data transmitted by the device. It is essential for users to be mindful of this vulnerability and ensure their devices are up to date to mitigate potential risks.

Affected Version(s)

Nest Labs Nest Labs Nest Cam IQ Indoor version 4620002

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.