216.73.216.6

CVE-2024-50384

· Published 02/04/2025 14:15 · Modified 02/04/2025 14:58

Labels: CVE-2024-50384 2025-04-02CVE-2024-50384CWE-459[email protected]

Essential information

Published
02/04/2025 14:15
Modified
02/04/2025 14:58
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Web Component HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
stmicroelectronics / x-cube-azrtos-wl cpe:2.3:a:stmicroelectronics:x-cube-azrtos-wl:2.0.0:*:*:*:*:*:*:*
stmicroelectronics / x-cube-azrtos-f7 cpe:2.3:a:stmicroelectronics:x-cube-azrtos-f7:1.1.0:*:*:*:*:*:*:*

References