PT-2025-14505 · Stmicroelectronics · Stmicroelectronics X-Cube-Azrtos-Wl

Kelly Patterson

·

Published

2025-04-02

·

Updated

2025-09-05

·

CVE-2024-50597

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions STMicroelectronics X-CUBE-AZRTOS-WL version 2.0.0
Description An integer underflow issue exists in the HTTP server's PUT request functionality, which can be triggered by a specially crafted network packet, leading to denial of service. This issue affects the NetX Duo Component HTTP Server implementation found in the nxd http server.c file.
Recommendations For version 2.0.0, consider disabling the HTTP server's PUT request functionality until a patch is available to prevent potential denial of service attacks. Restrict access to the NetX Duo Component HTTP Server implementation to minimize the risk of exploitation.

Exploit

Fix

DoS

Integer Underflow

Weakness Enumeration

Related Identifiers

CVE-2024-50597

Affected Products

Stmicroelectronics X-Cube-Azrtos-Wl