CVE-2024-42391: CWE-823 Use of Out-of-range Pointer Offset in Cesanta Mongoose Web Server
CVE-2024-42391 is a medium severity vulnerability in Cesanta Mongoose Web Server version 7.14 and earlier. It involves an out-of-range pointer offset triggered by sending an unexpected TLS packet, causing the application to read unintended heap memory. This flaw does not allow privilege escalation or denial of service but may expose limited information from memory. No official patch or remediation guidance is currently available from the vendor.
AI Analysis
Technical Summary
This vulnerability (CWE-823) in Cesanta Mongoose Web Server v7.14 and earlier arises from improper handling of TLS packets, allowing an attacker to cause the server to read memory outside the intended buffer boundaries. The issue is triggered by sending a specially crafted TLS packet, leading to out-of-range pointer dereference and unintended heap memory disclosure. The CVSS 3.1 base score is 4.3, reflecting low confidentiality impact with no integrity or availability impact. No known exploits are reported in the wild, and no vendor remediation level or patch information is currently provided.
Potential Impact
An attacker can send a malformed TLS packet to the vulnerable Mongoose Web Server, causing it to read unintended heap memory. This may lead to limited information disclosure but does not affect integrity or availability. There is no indication of privilege escalation or remote code execution from the available data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, consider restricting access to the affected server and monitoring for unusual TLS traffic patterns. No vendor-provided mitigation or temporary fix is currently documented.
CVE-2024-42391: CWE-823 Use of Out-of-range Pointer Offset in Cesanta Mongoose Web Server
Description
CVE-2024-42391 is a medium severity vulnerability in Cesanta Mongoose Web Server version 7.14 and earlier. It involves an out-of-range pointer offset triggered by sending an unexpected TLS packet, causing the application to read unintended heap memory. This flaw does not allow privilege escalation or denial of service but may expose limited information from memory. No official patch or remediation guidance is currently available from the vendor.
CVSS v3.1
Score 4.3medium
Affected software
pkg:github/Mongoose Web ServerRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-823) in Cesanta Mongoose Web Server v7.14 and earlier arises from improper handling of TLS packets, allowing an attacker to cause the server to read memory outside the intended buffer boundaries. The issue is triggered by sending a specially crafted TLS packet, leading to out-of-range pointer dereference and unintended heap memory disclosure. The CVSS 3.1 base score is 4.3, reflecting low confidentiality impact with no integrity or availability impact. No known exploits are reported in the wild, and no vendor remediation level or patch information is currently provided.
Potential Impact
An attacker can send a malformed TLS packet to the vulnerable Mongoose Web Server, causing it to read unintended heap memory. This may lead to limited information disclosure but does not affect integrity or availability. There is no indication of privilege escalation or remote code execution from the available data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, consider restricting access to the affected server and monitoring for unusual TLS traffic patterns. No vendor-provided mitigation or temporary fix is currently documented.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Nozomi
- Date Reserved
- 2024-07-31T12:51:37.204Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a9fcd15acd9273b495c3739
Added to database: 09/08/2026, 08:53:41 UTC
Last enriched: 09/08/2026, 09:07:38 UTC
Last updated: 09/08/2026, 09:07:38 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.