Critical severity9.8NVD Advisory· Published Nov 7, 2017· Updated May 13, 2026
CVE-2017-2922
CVE-2017-2922
Description
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause a buffer to be allocated while leaving stale pointers which leads to a use-after-free vulnerability which can be exploited to achieve remote code execution. An attacker needs to send a specially crafted websocket packet over the network to trigger this vulnerability.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.talosintelligence.com/vulnerability_reports/TALOS-2017-0429nvdExploitTechnical DescriptionThird Party Advisory
News mentions
0No linked articles in our index yet.