CVE-2019-5037
Description
An exploitable denial-of-service vulnerability exists in the Weave certificate loading functionality of Nest Cam IQ Indoor camera, version 4620002. A specially crafted weave packet can cause an integer overflow and an out-of-bounds read on unmapped memory to occur, resulting in a denial of service. An attacker can send a specially crafted packet to trigger.
CWE
- CWE-190 — CWE-190: Integer Overflow or Wraparound
Affected
- n/a / Nest Labs — v=Nest Labs Nest Cam IQ Indoor version 4620002 [affected]
CVSS
- 3.0 score=7.5 severity=HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0800 x_refsource_MISC
Source
cvelistV5-main/cves/2019/5xxx/CVE-2019-5037.json