CVE-2024-50384 Details
Description
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Web Component HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c
A denial-of-service vulnerability has been identified in the NetX Duo Web Component HTTP server of STMicroelectronics X-CUBE-AZRTOS-WL version 2.0.0. This vulnerability arises when the server processes an HTTP PUT request. If an error occurs after a file is opened for writing, the file is not properly closed. This oversight leads to subsequent HTTP requests involving file resources being met with a '404 File Not Found' error. The vulnerability can be triggered by sending a malicious packet with a 'Content-Length' value larger than the actual data in the first packet, causing a timeout and an incomplete file operation.
Developers can disable PUT request processing by terminating the PUT request handling in an application callback function.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2097 | CVE | |
| https://talosintelligence.com/vulnerability_reports/TALOS-2024-2097 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-459 | Incomplete Cleanup | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| st x-cube-azrt-h7rs | 1.0.0 |
CPE
Remediation
| |
| st x-cube-azrtos-f4 | 1.1.0 |
CPE
Remediation
| |
| st x-cube-azrtos-f7 | 1.1.0 |
CPE
Remediation
| |
| st x-cube-azrtos-g0 | 1.1.0 |
CPE
Remediation
| |
| st x-cube-azrtos-g4 | 2.0.0 |
CPE
Remediation
| |
| st x-cube-azrtos-h7 | 3.3.0 |
CPE
Remediation
| |
| st x-cube-azrtos-l4 | 2.0.0 |
CPE
Remediation
| |
| st x-cube-azrtos-l5 | 2.0.0 |
CPE
Remediation
| |
| st x-cube-azrtos-wb | 2.0.0 |
CPE
Remediation
| |
| st x-cube-azrtos-wl | 2.0.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Sep 5, 2025 | Initial Analysis | [email protected] |
| Apr 2, 2025 | New CVE Received | [email protected] |