Vulnerability Description
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cesanta | Mongoose | <= 7.14 |
Related Weaknesses (CWE)
References
- https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-42387Third Party Advisory
FAQ
What is CVE-2024-42387?
CVE-2024-42387 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space...
How severe is CVE-2024-42387?
CVE-2024-42387 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-42387?
Check the references section above for vendor advisories and patch information. Affected products include: Cesanta Mongoose.