Impact
A heap‑based buffer overflow occurs in the lib60870‑C 2.4.0 library when encoding FileSegment ASDU frames. The function only checks the standalone segment length and ignores the remaining capacity in the ASDU frame, allowing an attacker to overflow the heap. This overflow can corrupt adjacent data and potentially allow arbitrary code execution, compromising confidentiality, integrity, and availability. Based on the description, it is inferred that the buffer overflow can be triggered by specially crafted network packets sent to the server side of the library.
Affected Systems
The vulnerability affects systems that incorporate the lib60870‑C C library, version 2.4.0, which implements the IEC 60870‑5‑102 protocol used in industrial control and supervisory control and data acquisition (SCADA) environments. No other affected versions are listed in the available data.
Risk and Exploitability
The CVSS score is not provided, but a heap‑based overflow is typically considered high severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting that public exploits have not yet been documented. The attack vector is likely remote, via network traffic directed at the server side of the library. Breaches could lead to remote code execution, leading to full system compromise or denial of service if the overflow causes a crash.
OpenCVE Enrichment