CVE-2024-22013
Published Sep 16, 2024U-Boot environment is read from unauthenticated partition.
Vendor/product archive
3 CVEs tagged to google / nest_wifi_pro_firmware — 2 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
U-Boot environment is read from unauthenticated partition.
Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application
Google Nest WiFi Pro root code-execution & user-data compromise