摘要:
The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.
安全等级: Low
公告ID: KylinSec-SA-2024-3479
发布日期: 2024年8月30日
关联CVE: CVE-2024-32928
The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2024-32928 | KY3.4-5A | curl | Unaffected |
CVE-2024-32928 | KY3.5.2 | curl | Unaffected |
CVE-2024-32928 | V6 | curl | Unaffected |