CVE-2024-32928

The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:google:nest_mini_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_mini:-:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:haxx:libcurl:-:*:*:*:*:*:*:*

History

14 Mar 2025, 16:15

Type Values Removed Values Added
CWE CWE-295

Information

Published : 2024-08-19 17:15

Updated : 2025-03-14 16:15


NVD link : CVE-2024-32928

Mitre link : CVE-2024-32928

CVE.ORG link : CVE-2024-32928


JSON object : View

Products Affected

haxx

  • libcurl

google

  • nest_mini
  • nest_mini_firmware
CWE
NVD-CWE-noinfo CWE-295

Improper Certificate Validation