Information Disclosure in Nest Cam IQ Indoor Weave PASE Pairing Functionality
CVE-2019-5035
9CRITICAL
Summary
An information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor. By sending a series of specially crafted Weave packets, an attacker can brute-force the pairing code, allowing for expanded access to the Weave protocol and possibly full control over the device. This vulnerability highlights the importance of securing device pairing mechanisms to prevent unauthorized access.
Affected Version(s)
Nest Labs Nest Labs Nest Cam IQ Indoor version 4620002
References
CVSS V3.1
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved