Impact
The vulnerability arises when the MMS server processes a confirmed request PDU that contains an extended BER tag. The decoder, missing a bounds check, may advance its internal buffer incorrectly, resulting in a one‑byte out‑of‑bounds read on the heap. This triggers a crash of the MMS service process, causing the component to terminate and creating a denial‑of‑service condition for the affected system.
Affected Systems
MZ Automation GmbH’s libiec61850 library is affected. All releases prior to version 1.6.2 are vulnerable, as identified by the vendor. The fix is included in libiec61850 1.6.2.
Risk and Exploitability
The flaw can be exploited by an attacker who can send a crafted MMS confirmed request over an established IEC 61850 session. The EPSS score for this vulnerability is 0.00181 (i.e., <1%), and it is not listed in CISA KEV. The CVSS score of 6.9 indicates a moderate severity. The attack vector is likely remote over the network, requiring network access to the MMS service, and would result in a denial of service rather than data compromise.
OpenCVE Enrichment