Vulnerability Description
An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resulting in greater Weave access and potentially full device control. An attacker can send specially crafted packets to trigger this vulnerability.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nest Cam Iq Indoor Firmware | 4620002 | |
| Nest Cam Iq | - |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0798ExploitThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0798ExploitThird Party Advisory
FAQ
What is CVE-2019-5035?
CVE-2019-5035 is a vulnerability with a CVSS score of 9.0 (CRITICAL). An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force ...
How severe is CVE-2019-5035?
CVE-2019-5035 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-5035?
Check the references section above for vendor advisories and patch information. Affected products include: Google Nest Cam Iq Indoor Firmware, Google Nest Cam Iq.