CVE-2024-50596: Integer Underflow
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nxwebhttpserver.c
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50596?
CVE-2024-50596 is classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2024-50596?
To mitigate CVE-2024-50596, update STMicroelectronics X-CUBE-AZRTOS-WL to the latest version that addresses this integer underflow vulnerability.
What products are affected by CVE-2024-50596?
CVE-2024-50596 affects STMicroelectronics X-CUBE-AZRTOS-WL version 2.0.0.
Who can exploit CVE-2024-50596?
An attacker on the network can exploit CVE-2024-50596 by sending specially crafted network packets.
What kind of impact does CVE-2024-50596 have?
The impact of CVE-2024-50596 is denial of service, which can disrupt the HTTP server functionalities.