The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.
2024-08-19T17:15:07.557
2025-03-14T16:15:31.157
Modified
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | nest_mini_firmware | - | Yes | |
Hardware | nest_mini | - | No | |
Application | haxx | libcurl | - | Yes |