Lucene search

K
cveMitreCVE-2018-12716
HistoryJun 25, 2018 - 2:29 a.m.

CVE-2018-12716

2018-06-2502:29:00
CWE-200
mitre
web.nvd.nist.gov
33
cve-2018-12716
google home
chromecast
dns rebinding
geolocation
api security
vulnerability
nvd

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:L/Au:N/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

4.6

Confidence

High

EPSS

0.002

Percentile

60.4%

The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of these devices on its local network, extracting the scan_results bssid fields, and sending these fields in a geolocation/v1/geolocate Google Maps Geolocation API request.

Affected configurations

Nvd
Node
googlechromecast_firmwareMatch-
AND
googlechromecastMatch-
Node
googlehome_firmwareMatch-
AND
googlehomeMatch-
VendorProductVersionCPE
googlechromecast_firmware-cpe:2.3:o:google:chromecast_firmware:-:*:*:*:*:*:*:*
googlechromecast-cpe:2.3:h:google:chromecast:-:*:*:*:*:*:*:*
googlehome_firmware-cpe:2.3:o:google:home_firmware:-:*:*:*:*:*:*:*
googlehome-cpe:2.3:h:google:home:-:*:*:*:*:*:*:*

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:L/Au:N/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

4.6

Confidence

High

EPSS

0.002

Percentile

60.4%

Related for CVE-2018-12716