Impact
The flaw is an out-of-bounds read in the ACSE layer of the libiec61850 library, triggered when parsing AARQ PDUs during MMS connection establishment. An attacker who can influence the length field to zero or one causes the parser to read past the end of a heap buffer, potentially leaking sensitive memory contents and compromising confidentiality. The weakness is identified as CWE‑125.
Affected Systems
MZ Automation GmbH’s libiec61850 library is affected. Versions prior to 1.6.2 are vulnerable; the vendor recommends updating to 1.6.2 to receive a fix.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS score of < 1% indicates a very low exploitation probability and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. However, because the issue is triggered via network traffic in MMS sessions, a remote attacker with network access to an IEC 61850 implementation could craft a malicious AARQ PDU to obtain memory data. The risk is moderate, especially in environments where the library is exposed to untrusted network traffic.
OpenCVE Enrichment