Denial of Service Vulnerability in STMicroelectronics HTTP Server Component
CVE-2024-50385
6.5MEDIUM
What is CVE-2024-50385?
A vulnerability exists in the HTTP server functionality of the STMicroelectronics X-CUBE-AZRTOS-WL, which can be exploited by sending specially crafted network packets. This can result in a denial of service, effectively disrupting service availability and potentially impacting network security. The affected versions include X-CUBE-AZRTOS-F7 NetX Duo Component HTTP Server v 1.1.0, where the vulnerable code can be found in the nxd_http_server.c file. Immediate action is recommended to mitigate the risks associated with this vulnerability.
Affected Version(s)
X-CUBE-AZRT-H7RS 1.0.0
X-CUBE-AZRTOS-F4 1.1.0
X-CUBE-AZRTOS-F7 1.1.0