CVE-2024-50385
MEDIUMDescription
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Component HTTP Server HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c
Is your site exposed to CVE-2024-50385?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| st | x-cube-azrt-h7rs |
| st | x-cube-azrtos-f4 |
| st | x-cube-azrtos-f7 |
| st | x-cube-azrtos-g0 |
| st | x-cube-azrtos-g4 |
| st | x-cube-azrtos-h7 |
| st | x-cube-azrtos-l4 |
| st | x-cube-azrtos-l5 |
| st | x-cube-azrtos-wb |
| st | x-cube-azrtos-wl |
References
Frequently Asked Questions
What is CVE-2024-50385? +
How severe is CVE-2024-50385? +
What products are affected by CVE-2024-50385? +
How do I check if I'm vulnerable to CVE-2024-50385? +
Related Vulnerabilities
There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of …
Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virtual machine (VM) …
Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in …
IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.
SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The …
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache …