CVE-2019-5038: Openweave Openweave-Core
High severity, CVSS 8.8. EPSS: 2.7% chance of exploitation in the next 30 days.
An exploitable command execution vulnerability exists in the print-tlv command of Weave tool. A specially crafted weave TLV can trigger a stack-based buffer overflow, resulting in code execution. An attacker can trigger this vulnerability by convincing the user to open a specially crafted Weave command.
Affected products
- Openweave Openweave-Core: version 4.0.2 only
Published 2019-08-20. Last modified 2026-06-17.