Impact
The GOOSE subscriber in libiec61850 fails to validate the UTC timestamp field in unauthenticated IEC 61850 GOOSE messages. A malicious message that contains an undersized timestamp field can trigger a heap out‑of‑bounds read, causing the process to crash. The resulting crash creates a denial‑of‑service condition. This weakness is classified as CWE‑125.
Affected Systems
MZ Automation GmbH’s libiec61850 library is affected. All releases prior to the recommended 1.6.2 update are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability. The EPSS score is < 1%, and the vulnerability is not in the CISA KEV catalog. A remote attacker who can inject crafted GOOSE frames onto the network can exploit the flaw without authentication, leading to service disruption.
OpenCVE Enrichment