First published: Wed Apr 02 2025(Updated: )
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
STMicroelectronics X-CUBE-AZRTOS-WL |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-50596 is classified as a high severity vulnerability due to its potential to cause denial of service.
To mitigate CVE-2024-50596, update STMicroelectronics X-CUBE-AZRTOS-WL to the latest version that addresses this integer underflow vulnerability.
CVE-2024-50596 affects STMicroelectronics X-CUBE-AZRTOS-WL version 2.0.0.
An attacker on the network can exploit CVE-2024-50596 by sending specially crafted network packets.
The impact of CVE-2024-50596 is denial of service, which can disrupt the HTTP server functionalities.