CVE-2024-50597
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 2, 2025
CWE ID 191
Summary
CVE-2024-50597 is an integer underflow vulnerability discovered in STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0's HTTP server PUT request functionality. A malicious network packet can exploit this weakness, leading to denial of service. This issue lies within the NetX Duo Component HTTP Server implementation located at x-cube-azrtos-f7/Middlewares/ST/netxduo/addons/http/nxd_http_server.c. Unauthorized users can potentially trigger this vulnerability, causing potential disruptions to the affected system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.