Impact
The vulnerability is an out-of-bounds read (CWE‑125) that can be triggered when the lib60870 parsing routine processes malformed input. This flaw may cause the parsing process to crash, resulting in a denial of service. No other impact such as code execution or credential compromise is described in the official data.
Affected Systems
The affected product is MZ Automation lib60870. Versions older than 2.4.1 are known to contain the issue. No specific operating system or deployment context is mentioned in the CVE data.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be network-based, as the flaw occurs during parsing of input data; an attacker would need to supply crafted input to the component that uses the vulnerable library to trigger a crash and deny availability.
OpenCVE Enrichment