Vulnerability Description
An exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality of Nest Cam IQ Indoor version 4620002. A set of specially crafted weave packets can cause an out of bounds read, resulting in information disclosure. An attacker can send packets to trigger this vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nest Cam Iq Indoor Firmware | 4620002 | |
| Nest Cam Iq Indoor | - |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0797ExploitThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0797ExploitThird Party Advisory
FAQ
What is CVE-2019-5034?
CVE-2019-5034 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality of Nest Cam IQ Indoor version 4620002. A set of specially crafted weave packets can cause an out of...
How severe is CVE-2019-5034?
CVE-2019-5034 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-5034?
Check the references section above for vendor advisories and patch information. Affected products include: Google Nest Cam Iq Indoor Firmware, Google Nest Cam Iq Indoor.