Impact
A buffer over-read occurs in the MMS BER decoder when handling fixed-width boolean or integer fields. The decoder fails to validate an attacker‐supplied length value, resulting in a read past the end of a heap buffer. This flaw causes the MMS service process to terminate, producing a server‑side denial‑of‑service condition. The weakness is a classic out‑of‑bounds read, identified as CWE‑125.
Affected Systems
Vendor: MZ Automation GmbH; Product: libiec61850. All releases prior to 1.6.2 are affected; the vendor’s advisory recommends updating to version 1.6.2 to remove the flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating high severity. EPSS indicates a probability of exploitation below 1%, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is remote network traffic to the MMS service, where an attacker can craft a malformed MMS packet that triggers the over‑read and crashes the process, causing a denial of service.
OpenCVE Enrichment