CVE-2024-50597

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c
References
Link Resource
https://talosintelligence.com/vulnerability_reports/TALOS-2024-2103 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:st:x-cube-azrt-h7rs:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-f4:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-f7:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-g0:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-g4:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-h7:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-l4:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-l5:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-wb:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-wl:2.0.0:*:*:*:*:*:*:*

History

05 Sep 2025, 16:46

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de bajo flujo de enteros en el servidor HTTP, poner la funcionalidad de solicitud de STMicroelectronics X-Cube-Azrtos-WL 2.0.0. Un paquete de red especialmente manipulado puede conducir a la negación del servicio. Un atacante puede enviar un paquete malicioso para activar esta vulnerabilidad. Esta vulnerabilidad afecta la implementación del servidor HTTP del componente duo NetX que se puede encontrar en X-Cube-Azrtos-F7 \ MiddleWares \ ST \ NetXDUO \ Addons \ Http \ nxd_http_server.c
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2103 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2103 - Exploit, Third Party Advisory
CPE cpe:2.3:a:st:x-cube-azrtos-wb:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-wl:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-g0:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-f7:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-h7:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-l4:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrt-h7rs:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-f4:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-l5:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:st:x-cube-azrtos-g4:2.0.0:*:*:*:*:*:*:*
First Time St x-cube-azrt-h7rs
St x-cube-azrtos-h7
St x-cube-azrtos-g0
St x-cube-azrtos-wb
St x-cube-azrtos-l5
St x-cube-azrtos-l4
St x-cube-azrtos-wl
St x-cube-azrtos-g4
St x-cube-azrtos-f4
St
St x-cube-azrtos-f7

02 Apr 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-02 14:15

Updated : 2025-09-05 16:46


NVD link : CVE-2024-50597

Mitre link : CVE-2024-50597

CVE.ORG link : CVE-2024-50597


JSON object : View

Products Affected

st

  • x-cube-azrt-h7rs
  • x-cube-azrtos-l5
  • x-cube-azrtos-wl
  • x-cube-azrtos-g0
  • x-cube-azrtos-h7
  • x-cube-azrtos-l4
  • x-cube-azrtos-wb
  • x-cube-azrtos-f7
  • x-cube-azrtos-f4
  • x-cube-azrtos-g4
CWE
CWE-191

Integer Underflow (Wrap or Wraparound)