Information Disclosure in Nest Cam IQ Indoor Weave PASE Pairing Functionality
CVE-2019-5035

9CRITICAL

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
20 August 2019

Summary

An information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor. By sending a series of specially crafted Weave packets, an attacker can brute-force the pairing code, allowing for expanded access to the Weave protocol and possibly full control over the device. This vulnerability highlights the importance of securing device pairing mechanisms to prevent unauthorized access.

Affected Version(s)

Nest Labs Nest Labs Nest Cam IQ Indoor version 4620002

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.