Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-5035

Опубликовано: 20 авг. 2019
Источник: nvd
CVSS3: 9
CVSS3: 9
CVSS2: 6.8
EPSS Низкий

Описание

An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resulting in greater Weave access and potentially full device control. An attacker can send specially crafted packets to trigger this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:google:nest_cam_iq_indoor_firmware:4620002:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_cam_iq:-:*:*:*:*:*:*:*

EPSS

Процентиль: 67%
0.0054
Низкий

9 Critical

CVSS3

9 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-307
CWE-327

Связанные уязвимости

CVSS3: 9
github
больше 3 лет назад

An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resulting in greater Weave access and potentially full device control. An attacker can send specially crafted packets to trigger this vulnerability.

EPSS

Процентиль: 67%
0.0054
Низкий

9 Critical

CVSS3

9 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-307
CWE-327