« Volver al listado

CVE-2024-44097

Estado: AnalizadaCrítica (9.8)—

According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the either send the client a malicious response, or forward the (possibly modified) data to the real server."

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-44097",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-44097",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-02T16:56:15.661875Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "dsap-vuln-management@google.com",
      "affectedData": [
        {
          "vendor": "Google",
          "product": "Android",
          "versions": [
            {
              "status": "affected",
              "version": "unknown"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:google:nest_doorbell_battery_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "google",
          "product": "nest_doorbell_battery_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.73c",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:google:nest_cam_battery_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "google",
          "product": "nest_cam_battery_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.73c",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:google:nest_cam_floodlight_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "google",
          "product": "nest_cam_floodlight_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.73c",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:google:nest_cam_indoor_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "google",
          "product": "nest_cam_indoor_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.73c",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-10-02T14:15:05.670",
  "references": [
    {
      "url": "https://support.google.com/product-documentation/answer/14950962?sjid=9489879942601373169-NA",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "dsap-vuln-management@google.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "dsap-vuln-management@google.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "According to the researcher: \"The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the either send the client a malicious response, or forward the (possibly modified) data to the real server.\""
    },
    {
      "lang": "es",
      "value": "Según el investigador: \"Las conexiones TLS están cifradas para evitar manipulaciones o escuchas no autorizadas. Sin embargo, la aplicación no valida correctamente el certificado del servidor al inicializar la conexión TLS. Esto permite que un atacante de la red intercepte la conexión y lea los datos. El atacante podría enviar al cliente una respuesta maliciosa o reenviar los datos (posiblemente modificados) al servidor real\"."
    }
  ],
  "lastModified": "2026-06-17T07:52:17.930",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:google:nest_doorbell_\\(battery\\)_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64755C4C-152D-42E0-B8A6-85F8D3E12A49",
              "versionEndExcluding": "1.73c"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:google:nest_doorbell_\\(battery\\):-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "67E0B797-6C44-4E64-A5B3-D01CB6C649C3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:google:nest_cam_\\(outdoor_or_indoor\\,_battery\\)_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "94CCE5CC-CE98-4678-B310-DE4E2135A0AA",
              "versionEndExcluding": "1.73c"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:google:nest_cam_\\(outdoor_or_indoor\\,_battery\\):-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "49D395E2-8922-4083-BD14-8D2E6C5F4DA4"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:google:nest_cam_with_floodlight_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A122FAE-6A71-4B97-8F50-4B0BFB2ABBF2",
              "versionEndExcluding": "1.73c"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:google:nest_cam_with_floodlight:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9C64A31C-3CBC-42EF-B99B-51F5F3EDDE13"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:google:nest_cam_\\(indoor\\,_wired\\)_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9FA68A08-3C16-47C5-B37A-30510891CE5E",
              "versionEndExcluding": "1.73c"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:google:nest_cam_\\(indoor\\,_wired\\):-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CCBD77DA-4B12-4558-86A8-ADEC458221CF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "dsap-vuln-management@google.com"
}