First published: Wed Apr 02 2025(Updated: )
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Web Component HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
STMicroelectronics X-CUBE-AZRTOS-WL | ||
STMicroelectronics X-CUBE-AZRTOS-F7 NetX Duo Component HTTP Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-50384 has a high severity rating due to its potential for causing denial of service.
To fix CVE-2024-50384, ensure that you update to the latest version of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.1 or later, which addresses this vulnerability.
CVE-2024-50384 allows attackers to send specially crafted packets that can crash the HTTP server, resulting in a denial of service.
Yes, CVE-2024-50384 can be potentially exploited over the internet if the affected components are exposed.
CVE-2024-50384 affects users of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0 and STMicroelectronics X-CUBE-AZRTOS-F7 NetX Duo Web Component.