« Volver al listado

CVE-2024-45064

Estado: AnalizadaCrítica (9.8)—

A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS con AV:N/AC:L/PR:N/UI:N indica acceso remoto sin privilegios ni interacción: T1190. Buffer overflow en aplicación expuesta permite ejecución de código arbitrario (T1059) sin interacción del usuario.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (10)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-45064",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-45064",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-02T14:42:21.939802Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "talos-cna@cisco.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "talos-cna@cisco.com",
      "affectedData": [
        {
          "vendor": "STMicroelectronics",
          "product": "X-CUBE-AZRT-H7RS",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0"
            }
          ]
        },
        {
          "vendor": "STMicroelectronics",
          "product": "X-CUBE-AZRTOS-F4",
          "versions": [
            {
              "status": "affected",
              "version": "1.1.0"
            }
          ]
        },
        {
          "vendor": "STMicroelectronics",
          "product": "X-CUBE-AZRTOS-F7",
          "versions": [
            {
              "status": "affected",
              "version": "1.1.0"
            }
          ]
        },
        {
          "vendor": "STMicroelectronics",
          "product": "X-CUBE-AZRTOS-G0",
          "versions": [
            {
              "status": "affected",
              "version": "1.1.0"
            }
          ]
        },
        {
          "vendor": "STMicroelectronics",
          "product": "X-CUBE-AZRTOS-G4",
          "versions": [
            {
              "status": "affected",
              "version": "2.0.0"
            }
          ]
        },
        {
          "vendor": "STMicroelectronics",
          "product": "X-CUBE-AZRTOS-H7",
          "versions": [
            {
              "status": "affected",
              "version": "3.3.0"
            }
          ]
        },
        {
          "vendor": "STMicroelectronics",
          "product": "X-CUBE-AZRTOS-L4",
          "versions": [
            {
              "status": "affected",
              "version": "2.0.0"
            }
          ]
        },
        {
          "vendor": "STMicroelectronics",
          "product": "X-CUBE-AZRTOS-L5",
          "versions": [
            {
              "status": "affected",
              "version": "2.0.0"
            }
          ]
        },
        {
          "vendor": "STMicroelectronics",
          "product": "X-CUBE-AZRTOS-WB",
          "versions": [
            {
              "status": "affected",
              "version": "2.0.0"
            }
          ]
        },
        {
          "vendor": "STMicroelectronics",
          "product": "X-CUBE-AZRTOS-WL",
          "versions": [
            {
              "status": "affected",
              "version": "2.0.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-04-02T14:15:43.157",
  "references": [
    {
      "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2096",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "talos-cna@cisco.com"
    },
    {
      "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2096",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "talos-cna@cisco.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de desbordamiento del búfer en la funcionalidad de interfaz interna FileX Internal RAM de STMicroelectronics X-Cube-Azrtos-WL 2.0.0. Un conjunto especialmente manipulado de paquetes de red puede conducir a la ejecución del código. Un atacante puede enviar una secuencia de solicitudes para activar esta vulnerabilidad."
    }
  ],
  "lastModified": "2026-06-17T07:53:31.283",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:st:x-cube-azrt-h7rs:1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C5F8DB8-6A3C-492D-8B9D-2211A3FB2C07"
            },
            {
              "criteria": "cpe:2.3:a:st:x-cube-azrtos-f4:1.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A69A0188-96F6-40C7-A2BE-8760297E6249"
            },
            {
              "criteria": "cpe:2.3:a:st:x-cube-azrtos-f7:1.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FF242900-643B-444B-9DE7-0373C810EA22"
            },
            {
              "criteria": "cpe:2.3:a:st:x-cube-azrtos-g0:1.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CEE45297-82B1-4E0B-85DF-4A3C4EEC0391"
            },
            {
              "criteria": "cpe:2.3:a:st:x-cube-azrtos-g4:2.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D14B5944-7E42-45CD-8053-276C8787FC10"
            },
            {
              "criteria": "cpe:2.3:a:st:x-cube-azrtos-h7:3.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F44785CF-9D3D-44AB-8E92-50C9471C6481"
            },
            {
              "criteria": "cpe:2.3:a:st:x-cube-azrtos-l4:2.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9B78921-0E36-459A-AC17-94AC6AF8847F"
            },
            {
              "criteria": "cpe:2.3:a:st:x-cube-azrtos-l5:2.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58BA08A3-2A44-43CF-8302-082E44D1B070"
            },
            {
              "criteria": "cpe:2.3:a:st:x-cube-azrtos-wb:2.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "163D6B0F-2A31-401D-A1CD-EC77357767BC"
            },
            {
              "criteria": "cpe:2.3:a:st:x-cube-azrtos-wl:2.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CD0D34C-C260-4DC4-99A9-24F4C610C710"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "talos-cna@cisco.com"
}