CVE-2024-44097

According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the either send the client a malicious response, or forward the (possibly modified) data to the real server."
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:google:nest_doorbell_\(battery\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_doorbell_\(battery\):-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:google:nest_cam_\(outdoor_or_indoor\,_battery\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_cam_\(outdoor_or_indoor\,_battery\):-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:google:nest_cam_with_floodlight_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_cam_with_floodlight:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:google:nest_cam_\(indoor\,_wired\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_cam_\(indoor\,_wired\):-:*:*:*:*:*:*:*

History

24 Jul 2025, 15:58

Type Values Removed Values Added
CPE cpe:2.3:h:google:nest_cam_\(outdoor_or_indoor\,_battery\):-:*:*:*:*:*:*:*
cpe:2.3:o:google:nest_cam_\(indoor\,_wired\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:google:nest_cam_with_floodlight_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_cam_\(indoor\,_wired\):-:*:*:*:*:*:*:*
cpe:2.3:o:google:nest_doorbell_\(battery\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:google:nest_cam_\(outdoor_or_indoor\,_battery\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_cam_with_floodlight:-:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_doorbell_\(battery\):-:*:*:*:*:*:*:*
References () https://support.google.com/product-documentation/answer/14950962?sjid=9489879942601373169-NA - () https://support.google.com/product-documentation/answer/14950962?sjid=9489879942601373169-NA - Vendor Advisory
First Time Google nest Cam With Floodlight
Google nest Doorbell \(battery\) Firmware
Google nest Cam With Floodlight Firmware
Google
Google nest Cam \(outdoor Or Indoor\, Battery\) Firmware
Google nest Cam \(indoor\, Wired\) Firmware
Google nest Cam \(indoor\, Wired\)
Google nest Doorbell \(battery\)
Google nest Cam \(outdoor Or Indoor\, Battery\)

Information

Published : 2024-10-02 14:15

Updated : 2025-07-24 15:58


NVD link : CVE-2024-44097

Mitre link : CVE-2024-44097

CVE.ORG link : CVE-2024-44097


JSON object : View

Products Affected

google

  • nest_cam_\(outdoor_or_indoor\,_battery\)
  • nest_cam_with_floodlight_firmware
  • nest_cam_\(indoor\,_wired\)_firmware
  • nest_cam_\(outdoor_or_indoor\,_battery\)_firmware
  • nest_cam_with_floodlight
  • nest_cam_\(indoor\,_wired\)
  • nest_doorbell_\(battery\)
  • nest_doorbell_\(battery\)_firmware
CWE
CWE-269

Improper Privilege Management