CVE-2019-5040
Severity
7.5HIGH
EPSS
0.1%
top 68.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 20
Latest updateMay 24
Description
An exploitable information disclosure vulnerability exists in the Weave MessageLayer parsing of Openweave-core version 4.0.2 and Nest Cam IQ Indoor version 4620002. A specially crafted weave packet can cause an integer overflow to occur, resulting in PacketBuffer data reuse. An attacker can send a packet to trigger this vulnerability.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages3 packages
🔴Vulnerability Details
2GHSA▶
GHSA-v2rr-wfqp-88fw: An exploitable information disclosure vulnerability exists in the Weave MessageLayer parsing of Openweave-core version 4↗2022-05-24
CVEList▶
CVE-2019-5040: An exploitable information disclosure vulnerability exists in the Weave MessageLayer parsing of Openweave-core version 4↗2019-08-20