CVE-2024-42383
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field.
By exploiting this issue it is possible to write a NULL byte value beyond the memory space dedicated for the hostname field.
November 14, 2024
This issue affects Mongoose Web Server v7.14
CVE-2024-42383
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
4.2
It is highly recommended to not expose the vulnerable component inside an untrusted network.
Gabriele Quagliarella of Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more

