First published: Tue Aug 20 2019(Updated: )
An exploitable denial-of-service vulnerability exists in the Weave certificate loading functionality of Nest Cam IQ Indoor camera, version 4620002. A specially crafted weave packet can cause an integer overflow and an out-of-bounds read on unmapped memory to occur, resulting in a denial of service. An attacker can send a specially crafted packet to trigger.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Nest Cam IQ | =4620002 | |
Google Nest Cam IQ Indoor Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5037 is considered a high severity denial-of-service vulnerability affecting specific firmware versions of the Nest Cam IQ Indoor camera.
To mitigate CVE-2019-5037, update the Nest Cam IQ Indoor firmware to a version that addresses this vulnerability.
The denial-of-service in CVE-2019-5037 is caused by a specially crafted weave packet that leads to an integer overflow and an out-of-bounds read.
CVE-2019-5037 affects the Nest Cam IQ Indoor camera running firmware version 4620002.
Yes, CVE-2019-5037 can potentially be exploited remotely if an attacker sends specially crafted packets to the vulnerable device.