« Volver al listado

CVE-2024-22004

Estado: AnalizadaAlta (7.7)—

Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-22004",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-22004",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-29T15:53:35.353686Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "dsap-vuln-management@google.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 10,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 3.1
      }
    ]
  },
  "affected": [
    {
      "source": "dsap-vuln-management@google.com",
      "affectedData": [
        {
          "vendor": "Google",
          "product": "Nest Wifi Pro",
          "versions": [
            {
              "status": "affected",
              "version": "v11"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:google:nest_wifi_pro_firmware:11:*:*:*:*:*:*:*"
          ],
          "vendor": "google",
          "product": "nest_wifi_pro_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "11"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-04-05T18:15:09.100",
  "references": [
    {
      "url": "https://support.google.com/product-documentation/answer/14580222?hl=en&ref_topic=12974021&sjid=10751611047462550096-NA",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "dsap-vuln-management@google.com"
    },
    {
      "url": "https://support.google.com/product-documentation/answer/14580222?hl=en&ref_topic=12974021&sjid=10751611047462550096-NA",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "dsap-vuln-management@google.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application\n"
    },
    {
      "lang": "es",
      "value": "Debido a la longitud de la verificación, un atacante con acceso privilegiado a un sistema operativo Linux no seguro puede desencadenar una vulnerabilidad y filtrar la memoria segura de la aplicación de confianza."
    }
  ],
  "lastModified": "2026-06-17T07:10:30.907",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:google:nest_wifi_pro_firmware:24r1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79999C17-9D8E-4D29-A84A-913AAA0333DC"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:google:nest_wifi_pro:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "577F9028-2C7F-4161-8E5F-AA28DFE92AFC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:google:nest_wifi_point_firmware:24r1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53F40354-DCD0-4786-B5F0-FE99FD8DB60B"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:google:nest_wifi_point:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F09454DF-61F2-4AF0-9C0D-56026C1E0F0F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:google:nest_wifi_router_firmware:24r1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BE7082C-88A2-45CC-A1CF-93631BC2318F"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:google:nest_wifi_router:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BE37475C-41CA-49C4-AE4E-75B49BDF9232"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "dsap-vuln-management@google.com"
}