CVE-2023-48419

An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege 
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:google:nest_audio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_audio:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:google:nest_mini_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_mini:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:google:home_mini_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:home_mini:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:google:home_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:home:-:*:*:*:*:*:*:*

History

09 Jan 2024, 15:36

Type Values Removed Values Added
CPE cpe:2.3:h:google:nest_mini:-:*:*:*:*:*:*:*
cpe:2.3:h:google:home:-:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_audio:-:*:*:*:*:*:*:*
cpe:2.3:o:google:home_mini_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:google:nest_audio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:google:nest_mini_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:google:home_mini:-:*:*:*:*:*:*:*
cpe:2.3:o:google:home_firmware:*:*:*:*:*:*:*:*
First Time Google home Mini
Google
Google nest Audio
Google home
Google nest Audio Firmware
Google home Mini Firmware
Google nest Mini Firmware
Google home Firmware
Google nest Mini
CVSS v2 : unknown
v3 : 10.0
v2 : unknown
v3 : 9.8
References () https://support.google.com/product-documentation/answer/14273332?hl=en&ref_topic=12974021&sjid=4533873659772963473-NA#zippy=%2Cspeakers - () https://support.google.com/product-documentation/answer/14273332?hl=en&ref_topic=12974021&sjid=4533873659772963473-NA#zippy=%2Cspeakers - Vendor Advisory
CWE NVD-CWE-noinfo
Summary
  • (es) Un atacante en las proximidades wifi de un Google Home objetivo puede espiar a la víctima, lo que resulta en una elevación de privilegios.

02 Jan 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-02 19:15

Updated : 2024-01-09 15:36


NVD link : CVE-2023-48419

Mitre link : CVE-2023-48419

CVE.ORG link : CVE-2023-48419


JSON object : View

Products Affected

google

  • home_mini_firmware
  • home_firmware
  • nest_mini
  • home_mini
  • nest_mini_firmware
  • nest_audio
  • home
  • nest_audio_firmware
CWE
NVD-CWE-noinfo CWE-269

Improper Privilege Management