CVE-2019-5037: Integer Overflow
An exploitable denial-of-service vulnerability exists in the Weave certificate loading functionality of Nest Cam IQ Indoor camera, version 4620002. A specially crafted weave packet can cause an integer overflow and an out-of-bounds read on unmapped memory to occur, resulting in a denial of service. An attacker can send a specially crafted packet to trigger.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5037?
CVE-2019-5037 is considered a high severity denial-of-service vulnerability affecting specific firmware versions of the Nest Cam IQ Indoor camera.
How do I fix CVE-2019-5037?
To mitigate CVE-2019-5037, update the Nest Cam IQ Indoor firmware to a version that addresses this vulnerability.
What causes the denial-of-service in CVE-2019-5037?
The denial-of-service in CVE-2019-5037 is caused by a specially crafted weave packet that leads to an integer overflow and an out-of-bounds read.
Which devices are affected by CVE-2019-5037?
CVE-2019-5037 affects the Nest Cam IQ Indoor camera running firmware version 4620002.
Can CVE-2019-5037 be exploited remotely?
Yes, CVE-2019-5037 can potentially be exploited remotely if an attacker sends specially crafted packets to the vulnerable device.