CVE-2024-42385
4
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H
Summary
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cesanta | Mongoose Web Server | 0 <= 7.14 | affected |
Weaknesses
- CWE-140: CWE-140 Improper Neutralization of Delimiters
Workarounds
It is highly recommended to not expose the vulnerable component inside an untrusted network.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.