Skip to main content

Improper Neutralization of Delimiters

CVE-2024-42385

Severity Medium
Score 4/10

Summary

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.

  • HIGH
  • LOCAL
  • NONE
  • UNCHANGED
  • REQUIRED
  • HIGH
  • NONE
  • HIGH

CWE-140 - Improper Neutralization of Delimiters

The software does not neutralize or incorrectly neutralizes delimiters.

References

Advisory Timeline

  • Published