Impact
A stack-based buffer overflow exists in the libIEC61850 library, triggered by a maliciously crafted Read Request. This flaw can corrupt memory, potentially allowing an attacker to influence program control flow or compromise data integrity. The weakness corresponds to CWE‑121. The description explicitly states that the vulnerability could lead to memory corruption.
Affected Systems
The vulnerability affects MZ Automation’s libIEC61850, a library used in IEC 61850-based substation automation systems. No specific vulnerable version information is provided in the vendor advisory; the vendor recommends upgrading to the latest build available on GitHub.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score of < 1 % indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote network access, where an attacker sends a malformed Read Request to the library, which could trigger stack corruption or compromise system integrity.
OpenCVE Enrichment