CVE-2024-50594

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c
References
Link Resource
https://talosintelligence.com/vulnerability_reports/TALOS-2024-2102 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:st:x-cube-azrt-h7rs:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-f4:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-f7:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-g0:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-g4:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-h7:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-l4:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-l5:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-wb:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-wl:2.0.0:*:*:*:*:*:*:*

History

05 Sep 2025, 16:21

Type Values Removed Values Added
CPE cpe:2.3:a:st:x-cube-azrtos-l4:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-l5:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-f4:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-h7:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-wb:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-g0:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-g4:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-wl:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-f7:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrt-h7rs:1.0.0:*:*:*:*:*:*:*
Summary
  • (es) Existe una vulnerabilidad de bajo flujo de enteros en el servidor HTTP, poner la funcionalidad de solicitud de STMicroelectronics X-Cube-Azrtos-WL 2.0.0. Una serie especialmente manipulado de solicitudes de red puede conducir a la negación del servicio. Un atacante puede enviar una secuencia de paquetes maliciosos para desencadenar esta vulnerabilidad. Esta vulnerabilidad afecta la implementación del servidor HTTP de componente web NetX Duo que se puede encontrar en X-Cube-Azrtos-F7 \ MiddleWares \ ST \ NetXDUO \ Addons \ Web \ nx_web_http_server.c.C
First Time St x-cube-azrtos-g4
St x-cube-azrtos-wb
St x-cube-azrtos-g0
St x-cube-azrt-h7rs
St x-cube-azrtos-l4
St
St x-cube-azrtos-h7
St x-cube-azrtos-f7
St x-cube-azrtos-l5
St x-cube-azrtos-f4
St x-cube-azrtos-wl
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2102 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2102 - Exploit, Third Party Advisory

02 Apr 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-02 14:15

Updated : 2025-09-05 16:21


NVD link : CVE-2024-50594

Mitre link : CVE-2024-50594

CVE.ORG link : CVE-2024-50594


JSON object : View

Products Affected

st

  • x-cube-azrt-h7rs
  • x-cube-azrtos-h7
  • x-cube-azrtos-f7
  • x-cube-azrtos-wl
  • x-cube-azrtos-wb
  • x-cube-azrtos-g4
  • x-cube-azrtos-f4
  • x-cube-azrtos-l4
  • x-cube-azrtos-g0
  • x-cube-azrtos-l5
CWE
CWE-191

Integer Underflow (Wrap or Wraparound)