Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2024-39589 | Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters. | 
Solution
It is suggested to update the Mongoose Web Server library to v7.15.
Workaround
It is highly recommended to not expose the vulnerable component inside an untrusted network.
Tue, 19 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Cesanta Cesanta mongoose | |
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:cesanta:mongoose:*:*:*:*:*:*:*:* | |
| Vendors & Products | Cesanta Cesanta mongoose | 
Mon, 18 Nov 2024 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Mon, 18 Nov 2024 09:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters. | |
| Title | Improper Neutralization of Delimiters in Mongoose Web Server library | |
| Weaknesses | CWE-140 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2024-11-18T13:36:49.176Z
Reserved: 2024-07-31T12:51:37.203Z
Link: CVE-2024-42385
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-11-18T13:36:35.861Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-11-18T10:15:07.187
Modified: 2024-11-19T17:54:31.197
Link: CVE-2024-42385
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.