ZeroHour

CVE-2024-44097

CVSS 3.1
9.8 critical
EPSS
<1%p5
Published
()
Modified
Description

According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the either send the client a malicious response, or forward the (possibly modified) data to the real server."

Vendors
google
Products
nest doorbell \(battery\) firmware, nest cam \(outdoor or indoor\, battery\) firmware, nest cam with floodlight firmware, nest cam \(indoor\, wired\) firmware
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.