⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2019-5039Heap-based Buffer Overflow in Openweave-core

Severity
8.8HIGHNVD
EPSS
0.7%
top 28.73%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedAug 20
Latest updateMay 24

Description

An exploitable command execution vulnerability exists in the ASN1 certificate writing functionality of Openweave-core version 4.0.2. A specially crafted weave certificate can trigger a heap-based buffer overflow, resulting in code execution. An attacker can craft a weave certificate to trigger this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-mqw2-4hpp-cmw6: An exploitable command execution vulnerability exists in the ASN1 certificate writing functionality of Openweave-core version 42022-05-24
CVEList
CVE-2019-5039: An exploitable command execution vulnerability exists in the ASN1 certificate writing functionality of Openweave-core version 42019-08-20
VulnCheck
openweave openweave-core Heap-based Buffer Overflow2019
CVE-2019-5039 — Heap-based Buffer Overflow | cvebase