Vulnerability Description
Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nest Wifi Pro Firmware | 24r1 | |
| Nest Wifi Pro | - | |
| Nest Wifi Point Firmware | 24r1 | |
| Nest Wifi Point | - | |
| Nest Wifi Router Firmware | 24r1 | |
| Nest Wifi Router | - |
Related Weaknesses (CWE)
References
- https://support.google.com/product-documentation/answer/14580222?hl=en&ref_topicVendor Advisory
- https://support.google.com/product-documentation/answer/14580222?hl=en&ref_topicVendor Advisory
FAQ
What is CVE-2024-22004?
CVE-2024-22004 is a vulnerability with a CVSS score of 10.0 (CRITICAL). Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application
How severe is CVE-2024-22004?
CVE-2024-22004 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-22004?
Check the references section above for vendor advisories and patch information. Affected products include: Google Nest Wifi Pro Firmware, Google Nest Wifi Pro, Google Nest Wifi Point Firmware, Google Nest Wifi Point, Google Nest Wifi Router Firmware.