PT-2025-14503 · Netx Duo+1 · Netx Duo+1

Kelly Patterson

·

Publicado

2025-04-02

·

Atualizado

2025-09-05

·

CVE-2024-50595

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions STMicroelectronics X-CUBE-AZRTOS-WL version 2.0.0
Description An integer underflow issue exists in the HTTP server's PUT request functionality, which can lead to denial of service. This is due to the NetX Duo Component HTTP Server implementation. An attacker can trigger this issue by sending a sequence of malicious packets.
Recommendations For STMicroelectronics X-CUBE-AZRTOS-WL version 2.0.0, consider disabling the HTTP server's PUT request functionality until a patch is available. Restrict access to the nxd http server.c file to minimize the risk of exploitation. Avoid using the vulnerable NetX Duo Component HTTP Server implementation in the x-cube-azrtos-f7MiddlewaresST etxduoaddonshttp directory until the issue is resolved.

Exploit

Correção

DoS

Integer Underflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-50595

Produtos afetados

Netx Duo
Stmicroelectronics X-Cube-Azrtos-Wl