Vulnerabilities > CVE-2019-5039 - Out-of-bounds Write vulnerability in Openweave Openweave-Core 4.0.2

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

An exploitable command execution vulnerability exists in the ASN1 certificate writing functionality of Openweave-core version 4.0.2. A specially crafted weave certificate can trigger a heap-based buffer overflow, resulting in code execution. An attacker can craft a weave certificate to trigger this vulnerability.

Vulnerable Configurations

Part Description Count
Application
Openweave
1

Common Weakness Enumeration (CWE)

Talos

idTALOS-2019-0802
last seen2019-08-31
published2019-08-19
reporterTalos Intelligence
sourcehttp://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0802
titleNest Labs Openweave Weave ASN1Writer PutValue Code Execution Vulnerability