CVE-2024-32928: Medium severity google nest mini firmware vulnerability
The libcurl CURLOPTSSLVERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32928?
CVE-2024-32928 is considered a critical vulnerability due to the potential for man-in-the-middle attacks.
How do I fix CVE-2024-32928?
To fix CVE-2024-32928, ensure that the CURLOPT_SSL_VERIFYPEER option is enabled in the libcurl configuration.
Which devices are affected by CVE-2024-32928?
CVE-2024-32928 affects Google Nest Mini devices and any requests made by them utilizing libcurl.
What type of attacks can occur due to CVE-2024-32928?
CVE-2024-32928 allows for potential man-in-the-middle attacks on requests to Google cloud services.
Is there a workaround for CVE-2024-32928?
As a workaround for CVE-2024-32928, you can manually check SSL certificates for requests made using affected software.