CyberICT

CVE-2024-42391

Cesanta · Published November 18, 2024

CVSS v3.1

MEDIUM
Patch availableGet patch

Description

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

Affected Products

  • Mongoose <= 7.14

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N