Record summary

CVE-2019-5039 has a selected CVSS score of 8.8 (high). VulnCheck reports CVE-2019-5039 use in known ransomware campaigns.

Description

An exploitable command execution vulnerability exists in the ASN1 certificate writing functionality of Openweave-core version 4.0.2. A specially crafted weave certificate can trigger a heap-based buffer overflow, resulting in code execution. An attacker can craft a weave certificate to trigger this vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 26, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

Affected products and versions

2
ProductSourceVersion rangeStatus

Nest Labs

CVE ListNest Labs Openweave-core 4.0.2affected
VulnCheckVersion data not supplied

References

2