CVE-2019-5040
Description
An exploitable information disclosure vulnerability exists in the Weave MessageLayer parsing of Openweave-core version 4.0.2 and Nest Cam IQ Indoor version 4620002. A specially crafted weave packet can cause an integer overflow to occur, resulting in PacketBuffer data reuse. An attacker can send a packet to trigger this vulnerability.
CWE
- CWE-190 — CWE-190: Integer Overflow or Wraparound
Affected
- n/a / Nest Labs — v=Nest Labs Openweave-core 4.0.2 Nest Labs Nest Cam IQ Indoor version 4620002 [affected]
CVSS
- 3.0 score=8.2 severity=HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0803 x_refsource_MISC
Source
cvelistV5-main/cves/2019/5xxx/CVE-2019-5040.json