CVE-2024-42391

MEDIUM

Cesanta Mongoose Web Server <7.14 - Memory Corruption

Title source: llm
STIX 2.1

Description

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

Scores

CVSS v3 4.3
EPSS 0.0032
EPSS Percentile 55.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-823
Status published
Products (1)
cesanta/mongoose < 7.14
Published Nov 18, 2024
Tracked Since Feb 18, 2026