CVE-2024-32928
—CVSS 3.1
5.9 medium
EPSS
<1%p9
Published
()
Modified
Description
The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.
In the news0 stories
No ingested article mentions this CVE yet.