CVE-2024-32928

The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:google:nest_mini_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_mini:-:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:haxx:libcurl:-:*:*:*:*:*:*:*

History

20 Aug 2024, 16:13

Type Values Removed Values Added
Summary
  • (es) La opción libcurl CURLOPT_SSL_VERIFYPEER se deshabilitó en un subconjunto de solicitudes realizadas por dispositivos de producción Nest, lo que permitió un posible ataque de intermediario en solicitudes a los servicios en la nube de Google por parte de cualquier host por el que se enrutara el tráfico.
References () https://support.google.com/product-documentation/answer/14771247?hl=en&ref_topic=12974021&sjid=9111851316942032590-NA#zippy= - () https://support.google.com/product-documentation/answer/14771247?hl=en&ref_topic=12974021&sjid=9111851316942032590-NA#zippy= - Vendor Advisory
First Time Google nest Mini
Haxx
Haxx libcurl
Google nest Mini Firmware
Google
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
CPE cpe:2.3:o:google:nest_mini_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_mini:-:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:-:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo

19 Aug 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-19 17:15

Updated : 2024-08-20 16:13


NVD link : CVE-2024-32928

Mitre link : CVE-2024-32928

CVE.ORG link : CVE-2024-32928


JSON object : View

Products Affected

google

  • nest_mini_firmware
  • nest_mini

haxx

  • libcurl