Search

Find a vulnerability

Search criteria

    16 vulnerabilities by STMicroelectronics

    CVE-2024-50597 (GCVE-0-2024-50597)

    Vulnerability from nvd – Published: 2025-04-02 13:41 – Updated: 2025-11-03 19:31
    VLAI
    Summary
    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-02 15:00 UTC
    CWE
    • CWE-191 - Integer Underflow (Wrap or Wraparound)
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-50597",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-02T15:00:49.929887Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-02T15:01:25.085Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:31:55.240Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2103"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "X-CUBE-AZRT-H7RS",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G0",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-H7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.3.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L5",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WB",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WL",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Discovered by Kelly Patterson of Cisco Talos."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Component HTTP Server implementation which can be found in x-cube-azrtos-f7\\Middlewares\\ST\\netxduo\\addons\\http\\nxd_http_server.c"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-191",
                  "description": "CWE-191: Integer Underflow (Wrap or Wraparound)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-02T13:41:55.517Z",
            "orgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
            "shortName": "talos"
          },
          "references": [
            {
              "name": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2103",
              "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2103"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
        "assignerShortName": "talos",
        "cveId": "CVE-2024-50597",
        "datePublished": "2025-04-02T13:41:55.517Z",
        "dateReserved": "2024-10-25T19:20:52.221Z",
        "dateUpdated": "2025-11-03T19:31:55.240Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-50596 (GCVE-0-2024-50596)

    Vulnerability from nvd – Published: 2025-04-02 13:41 – Updated: 2025-11-03 19:31
    VLAI
    Summary
    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-02 15:06 UTC
    CWE
    • CWE-191 - Integer Underflow (Wrap or Wraparound)
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-50596",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-02T15:06:28.543056Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-02T15:06:46.402Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:31:53.881Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2103"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "X-CUBE-AZRT-H7RS",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G0",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-H7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.3.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L5",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WB",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WL",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Discovered by Kelly Patterson of Cisco Talos."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\\Middlewares\\ST\\netxduo\\addons\\web\\nx_web_http_server.c"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-191",
                  "description": "CWE-191: Integer Underflow (Wrap or Wraparound)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-02T13:41:55.311Z",
            "orgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
            "shortName": "talos"
          },
          "references": [
            {
              "name": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2103",
              "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2103"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
        "assignerShortName": "talos",
        "cveId": "CVE-2024-50596",
        "datePublished": "2025-04-02T13:41:55.311Z",
        "dateReserved": "2024-10-25T19:20:52.220Z",
        "dateUpdated": "2025-11-03T19:31:53.881Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-50595 (GCVE-0-2024-50595)

    Vulnerability from nvd – Published: 2025-04-02 13:41 – Updated: 2025-11-03 19:31
    VLAI
    Summary
    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-02 14:54 UTC
    CWE
    • CWE-191 - Integer Underflow (Wrap or Wraparound)
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-50595",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-02T14:54:45.845391Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-02T14:54:56.880Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:31:52.516Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2102"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "X-CUBE-AZRT-H7RS",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G0",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-H7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.3.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L5",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WB",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WL",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Discovered by Kelly Patterson of Cisco Talos."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Component HTTP Server implementation which can be found in x-cube-azrtos-f7\\Middlewares\\ST\\netxduo\\addons\\http\\nxd_http_server.c"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-191",
                  "description": "CWE-191: Integer Underflow (Wrap or Wraparound)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-02T13:41:56.435Z",
            "orgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
            "shortName": "talos"
          },
          "references": [
            {
              "name": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2102",
              "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2102"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
        "assignerShortName": "talos",
        "cveId": "CVE-2024-50595",
        "datePublished": "2025-04-02T13:41:56.435Z",
        "dateReserved": "2024-10-25T19:20:51.679Z",
        "dateUpdated": "2025-11-03T19:31:52.516Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-50594 (GCVE-0-2024-50594)

    Vulnerability from nvd – Published: 2025-04-02 13:41 – Updated: 2025-11-03 19:31
    VLAI
    Summary
    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-02 14:58 UTC
    CWE
    • CWE-191 - Integer Underflow (Wrap or Wraparound)
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-50594",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-02T14:58:32.955206Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-02T14:58:46.936Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:31:51.151Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2102"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "X-CUBE-AZRT-H7RS",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G0",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-H7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.3.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L5",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WB",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WL",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Discovered by Kelly Patterson of Cisco Talos."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\\Middlewares\\ST\\netxduo\\addons\\web\\nx_web_http_server.c"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-191",
                  "description": "CWE-191: Integer Underflow (Wrap or Wraparound)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-02T13:41:56.253Z",
            "orgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
            "shortName": "talos"
          },
          "references": [
            {
              "name": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2102",
              "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2102"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
        "assignerShortName": "talos",
        "cveId": "CVE-2024-50594",
        "datePublished": "2025-04-02T13:41:56.253Z",
        "dateReserved": "2024-10-25T19:20:51.679Z",
        "dateUpdated": "2025-11-03T19:31:51.151Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-50385 (GCVE-0-2024-50385)

    Vulnerability from nvd – Published: 2025-04-02 13:41 – Updated: 2025-11-03 19:31
    VLAI
    Summary
    A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Component HTTP Server HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-02 14:44 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-50385",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-02T14:44:04.971401Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-02T14:47:26.202Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:31:49.760Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2097"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "X-CUBE-AZRT-H7RS",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G0",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-H7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.3.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L5",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WB",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WL",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Discovered by Kelly Patterson of Cisco Talos."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Component HTTP Server HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\\Middlewares\\ST\\netxduo\\addons\\http\\nxd_http_server.c"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-459",
                  "description": "CWE-459: Incomplete Cleanup",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-02T13:41:57.295Z",
            "orgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
            "shortName": "talos"
          },
          "references": [
            {
              "name": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2097",
              "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2097"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
        "assignerShortName": "talos",
        "cveId": "CVE-2024-50385",
        "datePublished": "2025-04-02T13:41:57.295Z",
        "dateReserved": "2024-10-23T18:58:47.945Z",
        "dateUpdated": "2025-11-03T19:31:49.760Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-50384 (GCVE-0-2024-50384)

    Vulnerability from nvd – Published: 2025-04-02 13:41 – Updated: 2025-11-03 19:31
    VLAI
    Summary
    A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Web Component HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-02 14:49 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-50384",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-02T14:49:46.457709Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-02T14:49:58.452Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:31:48.392Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2097"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "X-CUBE-AZRT-H7RS",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G0",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-H7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.3.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L5",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WB",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WL",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Discovered by Kelly Patterson of Cisco Talos."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Web Component HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\\Middlewares\\ST\\netxduo\\addons\\web\\nx_web_http_server.c"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-459",
                  "description": "CWE-459: Incomplete Cleanup",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-02T13:41:57.136Z",
            "orgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
            "shortName": "talos"
          },
          "references": [
            {
              "name": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2097",
              "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2097"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
        "assignerShortName": "talos",
        "cveId": "CVE-2024-50384",
        "datePublished": "2025-04-02T13:41:57.136Z",
        "dateReserved": "2024-10-23T18:58:47.945Z",
        "dateUpdated": "2025-11-03T19:31:48.392Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-45064 (GCVE-0-2024-45064)

    Vulnerability from nvd – Published: 2025-04-02 13:41 – Updated: 2025-04-02 22:03
    VLAI
    Summary
    A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-02 14:42 UTC
    CWE
    • CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-45064",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-02T14:42:21.939802Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-02T14:42:32.552Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-04-02T22:03:12.067Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2096"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "X-CUBE-AZRT-H7RS",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G0",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-H7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.3.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L5",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WB",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WL",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Discovered by Kelly Patterson of Cisco Talos."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-119",
                  "description": "CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-02T13:41:58.080Z",
            "orgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
            "shortName": "talos"
          },
          "references": [
            {
              "name": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2096",
              "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2096"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
        "assignerShortName": "talos",
        "cveId": "CVE-2024-45064",
        "datePublished": "2025-04-02T13:41:58.080Z",
        "dateReserved": "2024-10-23T18:45:36.532Z",
        "dateUpdated": "2025-04-02T22:03:12.067Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-45064 (GCVE-0-2024-45064)

    Vulnerability from cvelistv5 – Published: 2025-04-02 13:41 – Updated: 2025-04-02 22:03
    VLAI
    Summary
    A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-02 14:42 UTC
    CWE
    • CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-45064",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-02T14:42:21.939802Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-02T14:42:32.552Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-04-02T22:03:12.067Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2096"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "X-CUBE-AZRT-H7RS",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G0",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-H7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.3.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L5",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WB",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WL",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Discovered by Kelly Patterson of Cisco Talos."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-119",
                  "description": "CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-02T13:41:58.080Z",
            "orgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
            "shortName": "talos"
          },
          "references": [
            {
              "name": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2096",
              "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2096"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
        "assignerShortName": "talos",
        "cveId": "CVE-2024-45064",
        "datePublished": "2025-04-02T13:41:58.080Z",
        "dateReserved": "2024-10-23T18:45:36.532Z",
        "dateUpdated": "2025-04-02T22:03:12.067Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-50385 (GCVE-0-2024-50385)

    Vulnerability from cvelistv5 – Published: 2025-04-02 13:41 – Updated: 2025-11-03 19:31
    VLAI
    Summary
    A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Component HTTP Server HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-02 14:44 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-50385",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-02T14:44:04.971401Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-02T14:47:26.202Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:31:49.760Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2097"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "X-CUBE-AZRT-H7RS",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G0",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-H7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.3.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L5",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WB",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WL",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Discovered by Kelly Patterson of Cisco Talos."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Component HTTP Server HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\\Middlewares\\ST\\netxduo\\addons\\http\\nxd_http_server.c"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-459",
                  "description": "CWE-459: Incomplete Cleanup",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-02T13:41:57.295Z",
            "orgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
            "shortName": "talos"
          },
          "references": [
            {
              "name": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2097",
              "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2097"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
        "assignerShortName": "talos",
        "cveId": "CVE-2024-50385",
        "datePublished": "2025-04-02T13:41:57.295Z",
        "dateReserved": "2024-10-23T18:58:47.945Z",
        "dateUpdated": "2025-11-03T19:31:49.760Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-50384 (GCVE-0-2024-50384)

    Vulnerability from cvelistv5 – Published: 2025-04-02 13:41 – Updated: 2025-11-03 19:31
    VLAI
    Summary
    A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Web Component HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-02 14:49 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-50384",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-02T14:49:46.457709Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-02T14:49:58.452Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:31:48.392Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2097"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "X-CUBE-AZRT-H7RS",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G0",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-H7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.3.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L5",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WB",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WL",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Discovered by Kelly Patterson of Cisco Talos."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Web Component HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\\Middlewares\\ST\\netxduo\\addons\\web\\nx_web_http_server.c"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-459",
                  "description": "CWE-459: Incomplete Cleanup",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-02T13:41:57.136Z",
            "orgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
            "shortName": "talos"
          },
          "references": [
            {
              "name": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2097",
              "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2097"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
        "assignerShortName": "talos",
        "cveId": "CVE-2024-50384",
        "datePublished": "2025-04-02T13:41:57.136Z",
        "dateReserved": "2024-10-23T18:58:47.945Z",
        "dateUpdated": "2025-11-03T19:31:48.392Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-50595 (GCVE-0-2024-50595)

    Vulnerability from cvelistv5 – Published: 2025-04-02 13:41 – Updated: 2025-11-03 19:31
    VLAI
    Summary
    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-02 14:54 UTC
    CWE
    • CWE-191 - Integer Underflow (Wrap or Wraparound)
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-50595",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-02T14:54:45.845391Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-02T14:54:56.880Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:31:52.516Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2102"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "X-CUBE-AZRT-H7RS",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G0",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-H7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.3.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L5",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WB",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WL",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Discovered by Kelly Patterson of Cisco Talos."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Component HTTP Server implementation which can be found in x-cube-azrtos-f7\\Middlewares\\ST\\netxduo\\addons\\http\\nxd_http_server.c"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-191",
                  "description": "CWE-191: Integer Underflow (Wrap or Wraparound)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-02T13:41:56.435Z",
            "orgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
            "shortName": "talos"
          },
          "references": [
            {
              "name": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2102",
              "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2102"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
        "assignerShortName": "talos",
        "cveId": "CVE-2024-50595",
        "datePublished": "2025-04-02T13:41:56.435Z",
        "dateReserved": "2024-10-25T19:20:51.679Z",
        "dateUpdated": "2025-11-03T19:31:52.516Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-50594 (GCVE-0-2024-50594)

    Vulnerability from cvelistv5 – Published: 2025-04-02 13:41 – Updated: 2025-11-03 19:31
    VLAI
    Summary
    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-02 14:58 UTC
    CWE
    • CWE-191 - Integer Underflow (Wrap or Wraparound)
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-50594",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-02T14:58:32.955206Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-02T14:58:46.936Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:31:51.151Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2102"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "X-CUBE-AZRT-H7RS",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G0",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-H7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.3.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L5",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WB",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WL",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Discovered by Kelly Patterson of Cisco Talos."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\\Middlewares\\ST\\netxduo\\addons\\web\\nx_web_http_server.c"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-191",
                  "description": "CWE-191: Integer Underflow (Wrap or Wraparound)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-02T13:41:56.253Z",
            "orgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
            "shortName": "talos"
          },
          "references": [
            {
              "name": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2102",
              "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2102"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
        "assignerShortName": "talos",
        "cveId": "CVE-2024-50594",
        "datePublished": "2025-04-02T13:41:56.253Z",
        "dateReserved": "2024-10-25T19:20:51.679Z",
        "dateUpdated": "2025-11-03T19:31:51.151Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-50597 (GCVE-0-2024-50597)

    Vulnerability from cvelistv5 – Published: 2025-04-02 13:41 – Updated: 2025-11-03 19:31
    VLAI
    Summary
    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-02 15:00 UTC
    CWE
    • CWE-191 - Integer Underflow (Wrap or Wraparound)
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-50597",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-02T15:00:49.929887Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-02T15:01:25.085Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:31:55.240Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2103"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "X-CUBE-AZRT-H7RS",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G0",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-H7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.3.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L5",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WB",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WL",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Discovered by Kelly Patterson of Cisco Talos."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Component HTTP Server implementation which can be found in x-cube-azrtos-f7\\Middlewares\\ST\\netxduo\\addons\\http\\nxd_http_server.c"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-191",
                  "description": "CWE-191: Integer Underflow (Wrap or Wraparound)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-02T13:41:55.517Z",
            "orgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
            "shortName": "talos"
          },
          "references": [
            {
              "name": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2103",
              "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2103"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
        "assignerShortName": "talos",
        "cveId": "CVE-2024-50597",
        "datePublished": "2025-04-02T13:41:55.517Z",
        "dateReserved": "2024-10-25T19:20:52.221Z",
        "dateUpdated": "2025-11-03T19:31:55.240Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-50596 (GCVE-0-2024-50596)

    Vulnerability from cvelistv5 – Published: 2025-04-02 13:41 – Updated: 2025-11-03 19:31
    VLAI
    Summary
    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-02 15:06 UTC
    CWE
    • CWE-191 - Integer Underflow (Wrap or Wraparound)
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-50596",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-02T15:06:28.543056Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-02T15:06:46.402Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:31:53.881Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2103"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "X-CUBE-AZRT-H7RS",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-F7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G0",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-G4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-H7",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.3.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L4",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-L5",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WB",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            },
            {
              "product": "X-CUBE-AZRTOS-WL",
              "vendor": "STMicroelectronics",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Discovered by Kelly Patterson of Cisco Talos."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\\Middlewares\\ST\\netxduo\\addons\\web\\nx_web_http_server.c"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-191",
                  "description": "CWE-191: Integer Underflow (Wrap or Wraparound)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-02T13:41:55.311Z",
            "orgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
            "shortName": "talos"
          },
          "references": [
            {
              "name": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2103",
              "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2103"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b",
        "assignerShortName": "talos",
        "cveId": "CVE-2024-50596",
        "datePublished": "2025-04-02T13:41:55.311Z",
        "dateReserved": "2024-10-25T19:20:52.220Z",
        "dateUpdated": "2025-11-03T19:31:53.881Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CERTFR-2022-AVI-169

    Vulnerability from certfr_avis - Published: 2022-02-22 - Updated: 2022-03-16

    Les vulnérabilités CVE-2021-43392 et CVE-2021-43393 ont été découvertes par l’ANSSI dans la Java Card J-SAFE3 et la plateforme STSAFE-J exposant une API Java Card 3.0.4, produits édités par STMicroelectronics.

    Ces vulnérabilités sont présentes dans l’implémentation de l’algorithme de signature ECDSA dans les produits STSAFE-J version 1.1.4 en configuration fermée et J-SAFE3 version 1.2.5. Elles permettent à un attaquant d’obtenir des informations sur des secrets cryptographiques et d’exploiter la vérification de signature dans des conditions particulières.

    Ces vulnérabilités sont exploitables pour STSAFE-J version 1.1.4 en configuration fermée et J-SIGN lorsque la vérification de signature est activée, mais pas pour JSAFE-3 EPASS BAS ni les produits EAC. Elles pourraient potentiellement être exploitées dans d’autres produits basés sur la plateforme Java Card J-SAFE-3.

    🇬🇧 ENGLISH VERSION [english-version]

    Two vulnerabilities have been discovered in STMicroelectronics products concerning the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card API. These vulnerabilities allow attackers to obtain information on cryptographic secrets and abuse the signature verification under certain circumstances. These vulnerabilities are exploitable for STSAFE-J version 1.1.4 in closed configuration and J-SIGN (when signature verification is activated) but not for J-SAFE3 EPASS BAC and EAC products. They might as well impact other products based on the J-SAFE-3 Java Card platform.

    Solution

    L’éditeur indique avoir informé ses clients.

    🇬🇧 The vendor indicates that customers were informed.

    Impacted products
    Vendor Product Description
    STMicroelectronics STSAFE-J STSAFE-J version 1.1.4 en configuration fermée
    STMicroelectronics J-SAFE3 J-SAFE3 version 1.2.5
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "STSAFE-J version 1.1.4 en configuration ferm\u00e9e",
          "product": {
            "name": "STSAFE-J",
            "vendor": {
              "name": "STMicroelectronics",
              "scada": false
            }
          }
        },
        {
          "description": "J-SAFE3 version 1.2.5",
          "product": {
            "name": "J-SAFE3",
            "vendor": {
              "name": "STMicroelectronics",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solution\n\nL\u2019\u00e9diteur indique avoir inform\u00e9 ses clients.\n\n\ud83c\uddec\ud83c\udde7 The vendor indicates that customers were informed.\n",
      "cves": [
        {
          "name": "CVE-2021-43393",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-43393"
        },
        {
          "name": "CVE-2021-43392",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-43392"
        }
      ],
      "initial_release_date": "2022-02-22T00:00:00",
      "last_revision_date": "2022-03-16T00:00:00",
      "links": [],
      "reference": "CERTFR-2022-AVI-169",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2022-02-22T00:00:00.000000"
        },
        {
          "description": "correction vecteur AC:H",
          "revision_date": "2022-03-16T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "Les vuln\u00e9rabilit\u00e9s CVE-2021-43392 et CVE-2021-43393 ont \u00e9t\u00e9 d\u00e9couvertes\npar l\u2019ANSSI dans la Java Card J-SAFE3 et la plateforme STSAFE-J exposant\nune API Java Card 3.0.4, produits \u00e9dit\u00e9s par STMicroelectronics.\n\nCes vuln\u00e9rabilit\u00e9s sont pr\u00e9sentes dans l\u2019impl\u00e9mentation de l\u2019algorithme\nde signature ECDSA dans les produits STSAFE-J version 1.1.4 en\nconfiguration ferm\u00e9e et J-SAFE3 version 1.2.5. Elles permettent \u00e0 un\nattaquant d\u2019obtenir des informations sur des secrets cryptographiques et\nd\u2019exploiter la v\u00e9rification de signature dans des conditions\nparticuli\u00e8res.\n\nCes vuln\u00e9rabilit\u00e9s sont exploitables pour STSAFE-J version 1.1.4 en\nconfiguration ferm\u00e9e et J-SIGN lorsque la v\u00e9rification de signature est\nactiv\u00e9e, mais pas pour JSAFE-3 EPASS BAS ni les produits EAC. Elles\npourraient potentiellement \u00eatre exploit\u00e9es dans d\u2019autres produits bas\u00e9s\nsur la plateforme Java Card J-SAFE-3.\n\n### \u003cspan lang=\"en-GB\"\u003e\u003cstrong\u003e\ud83c\uddec\ud83c\udde7 ENGLISH VERSION\u003c/strong\u003e\u003c/span\u003e [english-version]\n\n\u003cspan lang=\"en-US\"\u003eTwo vulnerabilities have been discovered in\nSTMicroelectronics products concerning the ECDSA signature algorithm on\nthe Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card\nAPI. These vulnerabilities allow attackers to obtain information on\ncryptographic secrets and abuse the signature verification under certain\ncircumstances. These vulnerabilities are exploitable for STSAFE-J\nversion 1.1.4 in closed configuration and J-SIGN (when signature\nverification is activated) but not for J-SAFE3 EPASS BAC and EAC\nproducts. They might as well impact other products based on the J-SAFE-3\nJava Card platform.\u003c/span\u003e\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits STMicroelectronics",
      "vendor_advisories": []
    }

    CERTFR-2019-AVI-595

    Vulnerability from certfr_avis - Published: 2019-11-27 - Updated: 2019-11-27

    Une vulnérabilité a été découverte dans les TPM STMicroelectronics. Elle permet à un attaquant de provoquer une atteinte à l'intégrité des données et une atteinte à la confidentialité des données.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    STMicroelectronics ST33TPHF2EI2C ST33TPHF2EI2C dont la version du microgiciel est antérieures à 73.65
    STMicroelectronics ST33TPHF2ESPI ST33TPHF2ESPI dont la version du microgiciel est antérieures à 73.64
    STMicroelectronics ST33TPHF2EI2C ST33TPHF2EI2C dont la version du microgiciel est antérieures à 73.21
    STMicroelectronics ST33TPHF20I2C ST33TPHF20I2C dont la version du microgiciel est antérieures à 74.65
    STMicroelectronics ST33TPHF20SPI ST33TPHF20SPI dont la version du microgiciel est antérieures à 74.20
    STMicroelectronics ST33TPHF2ESPI ST33TPHF2ESPI dont la version du microgiciel est antérieures à 71.16
    STMicroelectronics ST33TPHF20SPI ST33TPHF20SPI dont la version du microgiciel est antérieures à 74.64
    STMicroelectronics ST33TPHF2ESPI ST33TPHF2ESPI dont la version du microgiciel est antérieures à 73.20
    STMicroelectronics ST33TPHF20I2C ST33TPHF20I2C dont la version du microgiciel est antérieures à 74.21
    References
    Bulletin de sécurité STMicroelectronics 2019-11-13 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "ST33TPHF2EI2C dont la version du microgiciel est ant\u00e9rieures \u00e0 73.65",
          "product": {
            "name": "ST33TPHF2EI2C",
            "vendor": {
              "name": "STMicroelectronics",
              "scada": false
            }
          }
        },
        {
          "description": "ST33TPHF2ESPI dont la version du microgiciel est ant\u00e9rieures \u00e0 73.64",
          "product": {
            "name": "ST33TPHF2ESPI",
            "vendor": {
              "name": "STMicroelectronics",
              "scada": false
            }
          }
        },
        {
          "description": "ST33TPHF2EI2C dont la version du microgiciel est ant\u00e9rieures \u00e0 73.21",
          "product": {
            "name": "ST33TPHF2EI2C",
            "vendor": {
              "name": "STMicroelectronics",
              "scada": false
            }
          }
        },
        {
          "description": "ST33TPHF20I2C dont la version du microgiciel est ant\u00e9rieures \u00e0 74.65",
          "product": {
            "name": "ST33TPHF20I2C",
            "vendor": {
              "name": "STMicroelectronics",
              "scada": false
            }
          }
        },
        {
          "description": "ST33TPHF20SPI dont la version du microgiciel est ant\u00e9rieures \u00e0 74.20",
          "product": {
            "name": "ST33TPHF20SPI",
            "vendor": {
              "name": "STMicroelectronics",
              "scada": false
            }
          }
        },
        {
          "description": "ST33TPHF2ESPI dont la version du microgiciel est ant\u00e9rieures \u00e0 71.16",
          "product": {
            "name": "ST33TPHF2ESPI",
            "vendor": {
              "name": "STMicroelectronics",
              "scada": false
            }
          }
        },
        {
          "description": "ST33TPHF20SPI dont la version du microgiciel est ant\u00e9rieures \u00e0 74.64",
          "product": {
            "name": "ST33TPHF20SPI",
            "vendor": {
              "name": "STMicroelectronics",
              "scada": false
            }
          }
        },
        {
          "description": "ST33TPHF2ESPI dont la version du microgiciel est ant\u00e9rieures \u00e0 73.20",
          "product": {
            "name": "ST33TPHF2ESPI",
            "vendor": {
              "name": "STMicroelectronics",
              "scada": false
            }
          }
        },
        {
          "description": "ST33TPHF20I2C dont la version du microgiciel est ant\u00e9rieures \u00e0 74.21",
          "product": {
            "name": "ST33TPHF20I2C",
            "vendor": {
              "name": "STMicroelectronics",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2019-16863",
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-16863"
        }
      ],
      "initial_release_date": "2019-11-27T00:00:00",
      "last_revision_date": "2019-11-27T00:00:00",
      "links": [],
      "reference": "CERTFR-2019-AVI-595",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2019-11-27T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans les TPM STMicroelectronics. Elle\npermet \u00e0 un attaquant de provoquer une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des\ndonn\u00e9es et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans les TPM STMicroelectronics",
      "vendor_advisories": [
        {
          "published_at": "2019-11-13",
          "title": "Bulletin de s\u00e9curit\u00e9 STMicroelectronics",
          "url": "https://www.st.com/content/st_com/en/campaigns/tpm-update.html"
        }
      ]
    }