Man-in-the-Middle Vulnerability in Nest Production Devices Affecting Google Cloud Services
CVE-2024-32928
5.9MEDIUM
What is CVE-2024-32928?
A security flaw in Nest production devices has been identified, where the CURLOPT_SSL_VERIFYPEER option in libcurl was disabled for specific requests. This configuration weakness opens the door to potential man-in-the-middle attacks, allowing malicious actors to intercept and manipulate the communication between the affected devices and Google cloud services. As the traffic can be routed through any compromised host, this vulnerability poses a significant risk to the integrity and confidentiality of data exchanged with cloud services.
Affected Version(s)
Nest Speakers libcurl