Nest Security Bulletin—March 2024

Published March 25, 2024

You can find past Nest Security Bulletins in the archive.

This Nest Security Bulletin contains details of security vulnerabilities that previously affected Google Nest’s connected home devices.The vulnerabilities listed in this bulletin have been addressed. Devices started receiving (Over-the-Air) OTA updates in March 2024.

Security Patches

Vulnerabilities are grouped under the device family group and component that they affect. There is a description of the issue and a table with the CVE, associated references, type of vulnerability, and severity.

Vulnerabilities are based on the Common Vulnerabilities and Exposures (CVE) vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard.

 

Cameras & Doorbells

Software Version 1.71c

Firmware is the software installed on your Google Nest device. When a firmware update is available, your device will automatically download the update via an Over-the-Air (OTA) update.

List of Devices included in the update

Nest Doorbell (battery)

Nest Cam (outdoor or indoor, battery).     

Nest Cam with floodlight

Nest Cam (indoor, wired)

System

CVE 

Type 

Severity

CVE-2022-1587

ID

High 

Nest Wifi

Software Versions : 24R1

Firmware is the software installed on your Google Nest Wifi devices. When a firmware update is available, your device will automatically download the update via an Over-the-Air (OTA) update.

List of Devices included in the update

Nest Wifi Pro.                                                                 

Nest Wifi Point 

Nest Wifi Router

System

CVE 

Type 

Severity

CVE-2022-37434

EoP

High

CVE-2023-6339 ECE High
CVE-2024-22004 ID High

Kernel

CVE 

Type 

Severity

CVE-2023-20928

ID

High 

Nest Displays

Software Versions : f16

Firmware is the software installed on your Google Nest Wifi devices. When a firmware update is available, your device will automatically download the update via an Over-the-Air (OTA) update.

List of Devices included in the update

Google Nest Hub v2                                                            
Google Nest Hub Max

System

CVE 

Type 

Severity

CVE-2023-48419

EoP

High

Common questions and answers

This section answers common questions that may occur after reading this bulletin.

1. How do I determine if my device is updated to address these issues?

Firmware is the software installed on your Google Nest device. When a firmware update is available, your device will automatically download the update via an Over-the-Air (OTA) update.

Find your device's firmware version

2. What do the entries in the Type column mean?

Entries in the Type column of the vulnerability details table reference the classification of the security vulnerability.

Abbreviation

Definition

RCE

Remote code execution

EoP

Elevation of privilege

ID

Information disclosure

DoS

Denial of service

N/A

Classification not available 

Get help

Get answers from experts on the Google Nest Community or contact us.

Search
Clear search
Close search
Main menu
9489347794500919931
true
Search Help Center
true
true
true
false
false