CVE-2023-48419

An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of PrivilegeĀ 
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:google:nest_audio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_audio:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:google:nest_mini_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_mini:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:google:home_mini_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:home_mini:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:google:home_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:home:-:*:*:*:*:*:*:*

History

09 Jan 2024, 15:36

Type Values Removed Values Added
First Time Google nest Mini
Google
Google home Mini
Google nest Audio Firmware
Google home Firmware
Google nest Mini Firmware
Google nest Audio
Google home
Google home Mini Firmware
CPE cpe:2.3:h:google:home:-:*:*:*:*:*:*:*
cpe:2.3:o:google:nest_audio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:google:home_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_audio:-:*:*:*:*:*:*:*
cpe:2.3:o:google:nest_mini_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_mini:-:*:*:*:*:*:*:*
cpe:2.3:o:google:home_mini_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:home_mini:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://support.google.com/product-documentation/answer/14273332?hl=en&ref_topic=12974021&sjid=4533873659772963473-NA#zippy=%2CspeakersĀ - () https://support.google.com/product-documentation/answer/14273332?hl=en&ref_topic=12974021&sjid=4533873659772963473-NA#zippy=%2CspeakersĀ - Vendor Advisory
CWE NVD-CWE-noinfo

02 Jan 2024, 19:36

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-02 19:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-48419

Mitre link : CVE-2023-48419

CVE.ORG link : CVE-2023-48419


JSON object : View

Products Affected

google

  • home_mini
  • nest_audio
  • home
  • home_firmware
  • nest_audio_firmware
  • home_mini_firmware
  • nest_mini
  • nest_mini_firmware
CWE
NVD-CWE-noinfo CWE-269

Improper Privilege Management