The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.
References
Configurations
History
14 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-295 |
Information
Published : 2024-08-19 17:15
Updated : 2025-03-14 16:15
NVD link : CVE-2024-32928
Mitre link : CVE-2024-32928
CVE.ORG link : CVE-2024-32928
JSON object : View
Products Affected
haxx
- libcurl
- nest_mini
- nest_mini_firmware
CWE