Infinite Loop Bug in Cesanta Mongoose Web Server v7.14 Due to Improper Neutralization of Delimiters
CVE-2024-42392

7.5HIGH

Key Information:

Vendor

Cesanta

Status
Vendor
CVE Published:
18 November 2024

What is CVE-2024-42392?

The Cesanta Mongoose Web Server version 7.14 exhibits an improper neutralization of delimiters vulnerability that allows attackers to exploit the system by crafting input strings that contain unexpected characters. This flaw can lead to an infinite loop condition, causing potential Denial of Service (DoS) by monopolizing server resources and affecting overall system performance and availability. Website administrators using this version should implement necessary mitigations and consider upgrading to avoid exploitation of this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.