CVE-2019-9004

HIGH

Eclipse Wakaama - Memory Leak

Title source: rule

Description

In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a memory leak. Processing of a single crafted packet leads to leaking (wasting) 24 bytes of memory. This can lead to termination of the LWM2M server after exhausting all available memory.

Scores

CVSS v3 7.5
EPSS 0.0035
EPSS Percentile 57.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-401
Status published

Affected Products (1)

eclipse/wakaama

Timeline

Published Feb 22, 2019
Tracked Since Feb 18, 2026