CVE-2024-42386
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Nov 18, 2024
Updated: Nov 19, 2024
CWE ID 823
Summary
CVE-2024-42386 is a newly disclosed vulnerability in Cesanta Mongoose Web Server v7.14. This issue involves an Out-of-range Pointer Offset vulnerability, which allows an attacker to manipulate unexpected TLS packets and trigger a segmentation fault on the application. By exploiting this flaw, an adversary can potentially gain unauthorized access to the system or crash the web server. To mitigate this risk, it is recommended that users update to the latest version of Cesanta Mongoose Web Server as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Cesanta Software Limited