⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.
CVE-2019-5039 — Heap-based Buffer Overflow in Openweave-core
Severity
8.8HIGHNVD
EPSS
0.7%
top 28.73%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedAug 20
Latest updateMay 24
Description
An exploitable command execution vulnerability exists in the ASN1 certificate writing functionality of Openweave-core version 4.0.2. A specially crafted weave certificate can trigger a heap-based buffer overflow, resulting in code execution. An attacker can craft a weave certificate to trigger this vulnerability.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages1 packages
🔴Vulnerability Details
3GHSA▶
GHSA-mqw2-4hpp-cmw6: An exploitable command execution vulnerability exists in the ASN1 certificate writing functionality of Openweave-core version 4↗2022-05-24
CVEList▶
CVE-2019-5039: An exploitable command execution vulnerability exists in the ASN1 certificate writing functionality of Openweave-core version 4↗2019-08-20