Information Disclosure in Nest Cam IQ Indoor Weave PASE Pairing Functionality
CVE-2019-5035
9CRITICAL
What is CVE-2019-5035?
An information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor. By sending a series of specially crafted Weave packets, an attacker can brute-force the pairing code, allowing for expanded access to the Weave protocol and possibly full control over the device. This vulnerability highlights the importance of securing device pairing mechanisms to prevent unauthorized access.
Affected Version(s)
Nest Labs Nest Labs Nest Cam IQ Indoor version 4620002