Impact
The issue resides in the ISO Presentation layer of MZ Automation GmbH’s libiec61850 library. During normal mode negotiation, a missing length check while decoding presented data allows an attacker to supply a field with a zero length, which triggers a bounded heap overread before the MMS session is established. The overread causes the process to terminate, resulting in a denial of service for the affected system.
Affected Systems
The vulnerability affects the libiec61850 library distributed by MZ Automation GmbH. No specific version range is listed, but the vendor recommends updating to version 1.6.2 to resolve the flaw.
Risk and Exploitability
The CVSS score is 8.7, indicating a high severity vulnerability. EPSS score is < 1%, and the flaw is not listed in the CISA catalog. Attacks occur remotely via a crafted TCP connection to port 102 before the MMS session begins. Exploitation requires network reachability to the target device and does not provide information disclosure or privilege escalation; the impact is limited to causing the associated process to crash and deny service.
OpenCVE Enrichment