Impact
An off‑by‑one error in the GOOSE parser of libiec61850 causes a heap out‑of‑bounds read when certain message fields are processed. The read does not corrupt memory but forces the subscriber process to terminate, resulting in a denial‑of‑service condition on the affected platform.
Affected Systems
The flaw affects MZ Automation GmbH’s libiec61850 library. All releases prior to the vendor’s 1.6.2 update are impacted. Systems that depend on libiec61850 to decode IEC 61850 GOOSE frames must upgrade to avoid interruption.
Risk and Exploitability
The CVSS score of 7.1 reflects moderate‑to‑high severity, while the EPSS score of < 1 % indicates the vulnerability is rarely exploited in the wild and the lack of a KEV listing reinforces that it has not yet been widely used. An attacker must be able to inject a single un‑authenticated Layer‑2 multicast frame onto the plant process bus to trigger the flaw, which requires local or network proximity to the process bus.
OpenCVE Enrichment