CVE-2024-50595

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 2, 2025
CWE ID 191

Summary

CVE-2024-50595 is an integer underflow vulnerability discovered in STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0's HTTP server PUT request functionality. A malicious actor can cause a denial-of-service condition by crafting and sending a series of network requests to exploit this weakness. This vulnerability specifically targets the NetX Duo Component HTTP Server implementation located in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c. Unchecked integer values can lead to the underflow condition and subsequent crashing of the HTTP server.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share