CVE-2024-44097

According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the either send the client a malicious response, or forward the (possibly modified) data to the real server."
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:google:nest_doorbell_\(battery\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_doorbell_\(battery\):-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:google:nest_cam_\(outdoor_or_indoor\,_battery\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_cam_\(outdoor_or_indoor\,_battery\):-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:google:nest_cam_with_floodlight_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_cam_with_floodlight:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:google:nest_cam_\(indoor\,_wired\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_cam_\(indoor\,_wired\):-:*:*:*:*:*:*:*

History

24 Jul 2025, 15:58

Type Values Removed Values Added
References () https://support.google.com/product-documentation/answer/14950962?sjid=9489879942601373169-NA - () https://support.google.com/product-documentation/answer/14950962?sjid=9489879942601373169-NA - Vendor Advisory
CPE cpe:2.3:h:google:nest_cam_\(outdoor_or_indoor\,_battery\):-:*:*:*:*:*:*:*
cpe:2.3:o:google:nest_cam_\(outdoor_or_indoor\,_battery\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_cam_with_floodlight:-:*:*:*:*:*:*:*
cpe:2.3:o:google:nest_doorbell_\(battery\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:google:nest_cam_with_floodlight_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_cam_\(indoor\,_wired\):-:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_doorbell_\(battery\):-:*:*:*:*:*:*:*
cpe:2.3:o:google:nest_cam_\(indoor\,_wired\)_firmware:*:*:*:*:*:*:*:*
First Time Google nest Doorbell \(battery\)
Google nest Cam \(indoor\, Wired\) Firmware
Google nest Cam With Floodlight Firmware
Google nest Doorbell \(battery\) Firmware
Google nest Cam \(outdoor Or Indoor\, Battery\)
Google nest Cam \(indoor\, Wired\)
Google nest Cam With Floodlight
Google nest Cam \(outdoor Or Indoor\, Battery\) Firmware
Google

04 Oct 2024, 13:50

Type Values Removed Values Added
Summary
  • (es) Según el investigador: "Las conexiones TLS están cifradas para evitar manipulaciones o escuchas no autorizadas. Sin embargo, la aplicación no valida correctamente el certificado del servidor al inicializar la conexión TLS. Esto permite que un atacante de la red intercepte la conexión y lea los datos. El atacante podría enviar al cliente una respuesta maliciosa o reenviar los datos (posiblemente modificados) al servidor real".

02 Oct 2024, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

02 Oct 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-02 14:15

Updated : 2025-07-24 15:58


NVD link : CVE-2024-44097

Mitre link : CVE-2024-44097

CVE.ORG link : CVE-2024-44097


JSON object : View

Products Affected

google

  • nest_doorbell_\(battery\)
  • nest_cam_\(indoor\,_wired\)_firmware
  • nest_cam_\(outdoor_or_indoor\,_battery\)_firmware
  • nest_doorbell_\(battery\)_firmware
  • nest_cam_with_floodlight
  • nest_cam_\(outdoor_or_indoor\,_battery\)
  • nest_cam_\(indoor\,_wired\)
  • nest_cam_with_floodlight_firmware
CWE
CWE-269

Improper Privilege Management