CVE-2019-9004 describes a memory leak vulnerability in Eclipse Wakaama (formerly liblwm2m) version 1.0, specifically within the LWM2M server component. An attacker can trigger this by sending a single crafted packet containing invalid options, causing the server to leak 24 bytes of memory per packet. This issue has a CVSSv3 score of 7.5 (HIGH), indicating a high availability impact as repeated exploitation can exhaust all available memory, leading to a denial of service. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:eclipse:wakaama:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.