CVE-2024-35492: Null Pointer Dereference
Published May 29, 2024
·Updated
Cesanta Mongoose commit b316989 was discovered to contain a NULL pointer dereference via the scpy function at src/fmt.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MQTT packet.
Affected Software
1 affected component
Cesanta Mongoose
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 29, 2024
CVE Published
via NVD·08:15 PM
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Aug 20, 2024
Data Sourced
via MITRE·03:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35492?
The severity of CVE-2024-35492 is classified as high due to its potential to cause a Denial of Service.
2
How do I fix CVE-2024-35492?
To fix CVE-2024-35492, update to the latest version of Cesanta Mongoose where the vulnerability is patched.
3
What systems are affected by CVE-2024-35492?
CVE-2024-35492 affects Cesanta Mongoose software that utilizes the MQTT protocol.
4
What type of attack does CVE-2024-35492 enable?
CVE-2024-35492 enables attackers to cause a Denial of Service via a crafted MQTT packet.
5
Is CVE-2024-35492 easy to exploit?
Yes, CVE-2024-35492 can be exploited with relative ease by sending specially crafted messages.