Denial-of-Service Vulnerability in Nest Cam IQ Indoor Camera by Google
CVE-2019-5037
7.5HIGH
What is CVE-2019-5037?
A vulnerability within the Weave certificate loading functionality of the Nest Cam IQ Indoor camera allows for an exploitable denial-of-service condition. By crafting a specific Weave packet, an attacker can exploit an integer overflow, leading to an out-of-bounds read on unmapped memory. This situation can ultimately result in a denial of service, disrupting the normal functioning of the camera. Users should ensure their devices are updated to mitigate this risk.
Affected Version(s)
Nest Labs Nest Labs Nest Cam IQ Indoor version 4620002