7.7

CVE-2024-22004

Unchecked length in Trusted Application on Google Nest Wifi Pro, leading to out of bounds read

Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Nest Wifi Pro Firmware Version 24r1
   Google ≫ Nest Wifi Pro Version -
Google ≫ Nest Wifi Point Firmware Version 24r1
   Google ≫ Nest Wifi Point Version -
Google ≫ Nest Wifi Router Firmware Version 24r1
   Google ≫ Nest Wifi Router Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.145
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.7 3.1 4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
dsap-vuln-management@google.com 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://support.google.com/product-documentation/answer/14580222?hl=en&ref_topic=12974021&sjid=10751611047462550096-NA
Vendor Advisory