CVE-2024-45064 Details
Description
A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.
A buffer overflow vulnerability has been identified in the FileX Internal RAM interface of STMicroelectronics X-CUBE-AZRTOS-WL version 2.0.0. This vulnerability allows for code execution by overflowing a RAM disk buffer through a crafted sequence of network packets. The issue arises because the RAM disk driver can be improperly configured, enabling an attacker to exploit the buffer overflow via HTTP PUT requests.
To mitigate this vulnerability, ensure that the total sectors multiplied by the sector size is less than the size of the buffer allocated for the RAM disk memory when initializing the RAM disk with the `fx_media_format` function. This can be done by verifying that the total sectors and sector size values are set correctly to avoid exceeding the buffer size.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2096 | CVE | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2024-2096 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| st x-cube-azrt-h7rs | 1.0.0 |
CPE
Remediation
| |
| st x-cube-azrtos-f4 | 1.1.0 |
CPE
Remediation
| |
| st x-cube-azrtos-f7 | 1.1.0 |
CPE
Remediation
| |
| st x-cube-azrtos-g0 | 1.1.0 |
CPE
Remediation
| |
| st x-cube-azrtos-g4 | 2.0.0 |
CPE
Remediation
| |
| st x-cube-azrtos-h7 | 3.3.0 |
CPE
Remediation
| |
| st x-cube-azrtos-l4 | 2.0.0 |
CPE
Remediation
| |
| st x-cube-azrtos-l5 | 2.0.0 |
CPE
Remediation
| |
| st x-cube-azrtos-wb | 2.0.0 |
CPE
Remediation
| |
| st x-cube-azrtos-wl | 2.0.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 5, 2025 | Initial Analysis | [email protected] |
| Apr 2, 2025 | CVE Modified | CVE |
| Apr 2, 2025 | New CVE Received | [email protected] |