CVE-2024-42386

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 18, 2024
Updated: Nov 19, 2024
CWE ID 823

Summary

CVE-2024-42386 is a newly disclosed vulnerability in Cesanta Mongoose Web Server v7.14. This issue involves an Out-of-range Pointer Offset vulnerability, which allows an attacker to manipulate unexpected TLS packets and trigger a segmentation fault on the application. By exploiting this flaw, an adversary can potentially gain unauthorized access to the system or crash the web server. To mitigate this risk, it is recommended that users update to the latest version of Cesanta Mongoose Web Server as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share