Impact
The function deleteDataSetValuesShadowBuffer in the URCB Revalidation component has a use‑after‑free bug that can be triggered locally. The improper handling of memory leads to corruption and may allow an attacker to execute arbitrary code, thereby compromising confidentiality, integrity, or availability of the system. The weakness is classified as CWE‑119 and CWE‑416.
Affected Systems
The vulnerability affects the MZ Automation libiec61850 library up to and including version 1.6.1. Upgrading to version 1.6.2 or later eliminates the problem, as the patch identified by commit 486fd57f3aed65bb9d636ff00f9ddce2e450b168 restores correct memory management in deleteDataSetValuesShadowBuffer.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. A public exploit and proof‑of‑concept are available, demonstrating that the issue can be exploited locally by an attacker with access to the affected component.
OpenCVE Enrichment