cbcvebase.

Google Nest Cam Iq Indoor Firmware vulnerabilities

6 known vulnerabilities affecting google/nest_cam_iq_indoor_firmware.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2019-5035P3CRITICALCVSS 9.0v46200022019-08-20
CVE-2019-5035 [CRITICAL] CWE-307 CVE-2019-5035: An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality o An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resulting in greater Weave access and potentially full device control. An attacker can send specially crafted packets to trigger this v
nvd
CVE-2019-5040P3HIGHCVSS 7.5v46200022019-08-20
CVE-2019-5040 [HIGH] CWE-190 CVE-2019-5040: An exploitable information disclosure vulnerability exists in the Weave MessageLayer parsing of Open An exploitable information disclosure vulnerability exists in the Weave MessageLayer parsing of Openweave-core version 4.0.2 and Nest Cam IQ Indoor version 4620002. A specially crafted weave packet can cause an integer overflow to occur, resulting in PacketBuffer data reuse. An attacker can send a packet to trigger this vulnerability.
nvd
CVE-2019-5036P3HIGHCVSS 7.5v46200022019-08-20
CVE-2019-5036 [HIGH] CWE-284 CVE-2019-5036: An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session to close, resulting in a denial of service. An attacker can send a specially crafted packet to trigger this vulnerability.
nvd
CVE-2019-5037P3HIGHCVSS 7.5v46200022019-08-20
CVE-2019-5037 [HIGH] CWE-190 CVE-2019-5037: An exploitable denial-of-service vulnerability exists in the Weave certificate loading functionality An exploitable denial-of-service vulnerability exists in the Weave certificate loading functionality of Nest Cam IQ Indoor camera, version 4620002. A specially crafted weave packet can cause an integer overflow and an out-of-bounds read on unmapped memory to occur, resulting in a denial of service. An attacker can send a specially crafted packet to trig
nvd
CVE-2019-5043P4HIGHCVSS 7.5v46200022019-10-31
CVE-2019-5043 [HIGH] CWE-400 CVE-2019-5043: An exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, An exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, version 4620002. A set of TCP connections can cause unrestricted resource allocation, resulting in a denial of service. An attacker can connect multiple times to trigger this vulnerability.
nvd
CVE-2019-5034P4MEDIUMCVSS 5.3v46200022019-08-20
CVE-2019-5034 [MEDIUM] CWE-125 CVE-2019-5034: An exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality An exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality of Nest Cam IQ Indoor version 4620002. A set of specially crafted weave packets can cause an out of bounds read, resulting in information disclosure. An attacker can send packets to trigger this vulnerability.
nvd
Google Nest Cam Iq Indoor Firmware vulnerabilities | cvebase