First published: Wed Apr 02 2025(Updated: )
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
STMicroelectronics X-CUBE-AZRTOS-WL |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-50594 is classified as a critical severity vulnerability due to its potential to cause denial of service.
To fix CVE-2024-50594, update the STMicroelectronics X-CUBE-AZRTOS-WL to the latest version that addresses this vulnerability.
CVE-2024-50594 can be exploited through specially crafted network requests targeting the HTTP server's PUT request functionality.
CVE-2024-50594 affects STMicroelectronics X-CUBE-AZRTOS-WL version 2.0.0.
The potential impact of CVE-2024-50594 is a denial of service, which disrupts the availability of the affected HTTP server.