Openweave is a connectivity and messaging framework that operates as a core component in IoT and smart-home device ecosystems, presenting a narrowly scoped but strategically positioned attack surface. Its observed vulnerabilities cluster around memory-safety issues including out-of-bounds writes, heap and stack buffer overflows, and integer wraparound conditions, which are characteristic of low-level embedded protocols. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openweave over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5039HIGH An exploitable command execution vulnerability exists in the ASN1 certificate writing functionality of Openweave-core version 4.0.2. A specially crafted weave certificate can trigg | Aug 20, 2019 | 8.8 | 25 | NO | NO |
CVE-2019-5040HIGH An exploitable information disclosure vulnerability exists in the Weave MessageLayer parsing of Openweave-core version 4.0.2 and Nest Cam IQ Indoor version 4620002. A specially cra | Aug 20, 2019 | 7.5 | 23 | NO | NO |
CVE-2019-5038HIGH An exploitable command execution vulnerability exists in the print-tlv command of Weave tool. A specially crafted weave TLV can trigger a stack-based buffer overflow, resulting in | Aug 20, 2019 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openweave.
Media articles that mention a CVE ID that affects a product developed by Openweave — matched by CVE ID, not by vendor name.