VDB
CVE-2024-32928
CVE-2024-32928
PUBLISHED
CVSS 5.900000095367432 MEDIUM
The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.
EPSS 0.19% · 9.3th percentile
Risk Scores
CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.19%
9.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nest Speakers | libcurl, libcurl | |
| haxx | libcurl | |
| nest_mini_firmware |
Timeline
- Aug 19, 2024 CVE Published
- Aug 19, 2024 PoC Published
- Aug 20, 2024 EPSS Score
- Sep 10, 2024 EPSS Score
- Sep 30, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 21, 2024 EPSS Score
- Nov 11, 2024 EPSS Score
- Dec 3, 2024 EPSS Score
- Dec 23, 2024 EPSS Score
- Jan 13, 2025 EPSS Score
- Feb 3, 2025 EPSS Score