Impact
A local heap-based buffer overflow was found in the SVReceiver_stopThreadless function of the ASDU Element Handler in libiec61850. The overflow occurs when malicious input is processed in sv_subscriber.c, potentially corrupting dynamic memory. This weakness corresponds to CWE‑119 and CWE‑122 and can lead to application crashes or, if code is injected, arbitrary local code execution.
Affected Systems
MZ Automation’s libiec61850 library, versions up to and including 1.6.1, is affected. The flaw resides in the sampled‑values component. Version 1.6.2 contains the bug fix and is not vulnerable.
Risk and Exploitability
The CVSS score of 4.8 classifies the issue as moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Because the attack vector is local, exploitation requires physical or network-level local access to the device or system running libiec61850. Public exploits have been released, so an attacker with local privileges can potentially crash or take over the affected component.
OpenCVE Enrichment