An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session to close, resulting in a denial of service. An attacker can send a specially crafted packet to trigger this vulnerability.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0799 | third party advisory exploit |