CVE-2024-50594: Integer Underflow
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nxwebhttpserver.c
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50594?
CVE-2024-50594 is classified as a critical severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2024-50594?
To fix CVE-2024-50594, update the STMicroelectronics X-CUBE-AZRTOS-WL to the latest version that addresses this vulnerability.
What types of attacks can exploit CVE-2024-50594?
CVE-2024-50594 can be exploited through specially crafted network requests targeting the HTTP server's PUT request functionality.
What systems are affected by CVE-2024-50594?
CVE-2024-50594 affects STMicroelectronics X-CUBE-AZRTOS-WL version 2.0.0.
What is the potential impact of CVE-2024-50594?
The potential impact of CVE-2024-50594 is a denial of service, which disrupts the availability of the affected HTTP server.