Infinite Loop Bug in Cesanta Mongoose Web Server v7.14 Due to Improper Neutralization of Delimiters
CVE-2024-42392

4MEDIUM

Key Information:

Vendor

Cesanta

Vendor
CVE Published:
18 November 2024

What is CVE-2024-42392?

The Cesanta Mongoose Web Server version 7.14 exhibits an improper neutralization of delimiters vulnerability that allows attackers to exploit the system by crafting input strings that contain unexpected characters. This flaw can lead to an infinite loop condition, causing potential Denial of Service (DoS) by monopolizing server resources and affecting overall system performance and availability. Website administrators using this version should implement necessary mitigations and consider upgrading to avoid exploitation of this vulnerability.

Affected Version(s)

Mongoose Web Server 0 <= 7.14

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.