CVE-2024-50596

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c
References
Link Resource
https://talosintelligence.com/vulnerability_reports/TALOS-2024-2103 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:st:x-cube-azrt-h7rs:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-f4:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-f7:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-g0:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-g4:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-h7:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-l4:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-l5:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-wb:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-wl:2.0.0:*:*:*:*:*:*:*

History

05 Sep 2025, 16:46

Type Values Removed Values Added
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2103 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2103 - Exploit, Third Party Advisory
CPE cpe:2.3:a:st:x-cube-azrtos-l4:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-l5:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-f4:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-h7:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-wb:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-g0:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-g4:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-wl:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-f7:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrt-h7rs:1.0.0:*:*:*:*:*:*:*
Summary
  • (es) Existe una vulnerabilidad de bajo flujo de enteros en el servidor HTTP, poner la funcionalidad de solicitud de STMicroelectronics X-Cube-Azrtos-WL 2.0.0. Un paquete de red especialmente manipulado puede conducir a la negación del servicio. Un atacante puede enviar un paquete malicioso para activar esta vulnerabilidad. Esta vulnerabilidad afecta la implementación del servidor HTTP de componente web de duo NetX que se puede encontrar en X-Cube-Azrtos-F7 \ MiddleWares \ ST \ NetXDUO \ Addons \ Web \ nx_web_http_server.c
First Time St x-cube-azrtos-g4
St x-cube-azrtos-wb
St x-cube-azrtos-g0
St x-cube-azrt-h7rs
St x-cube-azrtos-l4
St
St x-cube-azrtos-h7
St x-cube-azrtos-f7
St x-cube-azrtos-l5
St x-cube-azrtos-f4
St x-cube-azrtos-wl

02 Apr 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-02 14:15

Updated : 2025-09-05 16:46


NVD link : CVE-2024-50596

Mitre link : CVE-2024-50596

CVE.ORG link : CVE-2024-50596


JSON object : View

Products Affected

st

  • x-cube-azrt-h7rs
  • x-cube-azrtos-h7
  • x-cube-azrtos-f7
  • x-cube-azrtos-wl
  • x-cube-azrtos-wb
  • x-cube-azrtos-g4
  • x-cube-azrtos-f4
  • x-cube-azrtos-l4
  • x-cube-azrtos-g0
  • x-cube-azrtos-l5
CWE
CWE-191

Integer Underflow (Wrap or Wraparound)