Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-30698 | The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through. |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 14 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-295 |
Tue, 20 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google nest Mini Google nest Mini Firmware Haxx Haxx libcurl |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:haxx:libcurl:-:*:*:*:*:*:*:* cpe:2.3:h:google:nest_mini:-:*:*:*:*:*:*:* cpe:2.3:o:google:nest_mini_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Google
Google nest Mini Google nest Mini Firmware Haxx Haxx libcurl |
|
| Metrics |
cvssV3_1
|
Mon, 19 Aug 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 19 Aug 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through. | |
| References |
|
Status: PUBLISHED
Assigner: Google_Devices
Published:
Updated: 2025-03-14T15:47:28.052Z
Reserved: 2024-04-19T15:12:13.576Z
Link: CVE-2024-32928
Updated: 2024-08-19T19:22:22.783Z
Status : Modified
Published: 2024-08-19T17:15:07.557
Modified: 2025-03-14T16:15:31.157
Link: CVE-2024-32928
No data.
OpenCVE Enrichment
No data.
EUVD