CVE-2024-22004

Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:google:nest_wifi_pro_firmware:24r1:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_wifi_pro:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:google:nest_wifi_point_firmware:24r1:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_wifi_point:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:google:nest_wifi_router_firmware:24r1:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_wifi_router:-:*:*:*:*:*:*:*

History

24 Jul 2025, 18:04

Type Values Removed Values Added
References () https://support.google.com/product-documentation/answer/14580222?hl=en&ref_topic=12974021&sjid=10751611047462550096-NA - () https://support.google.com/product-documentation/answer/14580222?hl=en&ref_topic=12974021&sjid=10751611047462550096-NA - Vendor Advisory
First Time Google nest Wifi Pro
Google nest Wifi Point Firmware
Google
Google nest Wifi Router
Google nest Wifi Point
Google nest Wifi Pro Firmware
Google nest Wifi Router Firmware
CWE CWE-125
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.7
CPE cpe:2.3:o:google:nest_wifi_router_firmware:24r1:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_wifi_point:-:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_wifi_router:-:*:*:*:*:*:*:*
cpe:2.3:h:google:nest_wifi_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:google:nest_wifi_point_firmware:24r1:*:*:*:*:*:*:*
cpe:2.3:o:google:nest_wifi_pro_firmware:24r1:*:*:*:*:*:*:*

05 Apr 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-05 18:15

Updated : 2025-07-24 18:04


NVD link : CVE-2024-22004

Mitre link : CVE-2024-22004


JSON object : View

Products Affected

google

  • nest_wifi_point
  • nest_wifi_router_firmware
  • nest_wifi_router
  • nest_wifi_pro
  • nest_wifi_pro_firmware
  • nest_wifi_point_firmware
CWE
CWE-125

Out-of-bounds Read