VendorsMZ-Automationlibiec61850all versions
Vulnerabilities

MZ-Automation libIEC61850

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

35CVEs
CVE-2022-2972
MZ Automation libIEC61850 Stack-Based Buffer Overflow
Published 2022-09-23 · Modified
10.0EPSS 0.016
CVE-2022-2970
MZ Automation libIEC61850 Stack-Based Buffer Overflow
Published 2022-09-23 · Modified
10.0EPSS 0.015
CVE-2018-18957
An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c.
Published 2018-11-05 · Modified
9.81 PoCEPSS 0.116
CVE-2018-19185
An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c. This is exploitable even after CVE-2018-18834 has been patched, with a different dataSetValue sequence than the CVE-2018-18834 attack vector.
Published 2018-11-12 · Modified
9.8EPSS 0.021
CVE-2018-18834
An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c.
Published 2018-10-30 · Modified
9.8EPSS 0.021
CVE-2020-15158
Heap buffer overflow in libIEC61850
Published 2020-08-26 · Modified
9.8EPSS 0.020
CVE-2024-45970
Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via the MMS FileDirResponse message.
Published 2024-11-15 · Analyzed
9.8EPSS 0.006
CVE-2024-45971
Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0 allow a malicious server to cause a stack-based buffer overflow via the MMS IdentifyResponse message.
Published 2024-11-15 · Analyzed
9.8EPSS 0.006
CVE-2019-19931
In libIEC61850 1.4.0, MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c has a heap-based buffer overflow.
Published 2019-12-23 · Modified
8.8EPSS 0.013
CVE-2020-7054
MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c in libIEC61850 through 1.4.0 has a heap-based buffer overflow when parsing the MMS_BIT_STRING data type.
Published 2020-01-14 · Modified
8.8EPSS 0.011
CVE-2022-3976
MZ Automation libiec61850 MMS File Services mms_client_files.c path traversal
Published 2022-11-13 · Modified
8.8EPSS 0.005
CVE-2022-2973
MZ Automation libIEC61850 NULL Pointer Dereference
Published 2022-09-23 · Modified
8.6EPSS 0.011
CVE-2022-2971
MZ Automation libIEC61850 Access of Resource Using Incompatible Type ('Type Confusion')
Published 2022-09-23 · Modified
8.6EPSS 0.011
CVE-2022-21159
A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec61850 1.5.0. A specially-crafted series of network requests can lead to denial of service. An attacker can send a sequence of malformed iec61850 messages to trigger this vulnerability.
Published 2022-04-15 · Modified
7.5EPSS 0.018
CVE-2018-18937
An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in ClientDataSet_getValues in client/ied_connection.c.
Published 2018-11-05 · Modified
7.5EPSS 0.017
CVE-2018-19093
An issue has been found in libIEC61850 v1.3. It is a SEGV in ControlObjectClient_setCommandTerminationHandler in client/client_control.c. NOTE: the software maintainer disputes this because it requires incorrect usage of the client_example_control program
Published 2018-11-07 · Modified
7.5EPSS 0.017
CVE-2019-6135
An issue has been found in libIEC61850 v1.3.1. Memory_malloc in hal/memory/lib_memory.c has a memory leak when called from Asn1PrimitiveValue_create in mms/asn1/asn1_ber_primitive_value.c, as demonstrated by goose_publisher_example.c and iec61850_9_2_LE_example.c.
Published 2019-01-11 · Modified
7.5EPSS 0.017
CVE-2019-6136
An issue has been found in libIEC61850 v1.3.1. Ethernet_setProtocolFilter in hal/ethernet/linux/ethernet_linux.c has a SEGV, as demonstrated by sv_subscriber_example.c and sv_subscriber.c.
Published 2019-01-11 · Modified
7.5EPSS 0.015
CVE-2019-6138
An issue has been found in libIEC61850 v1.3.1. Memory_malloc and Memory_calloc in hal/memory/lib_memory.c have memory leaks when called from mms/iso_mms/common/mms_value.c, server/mms_mapping/mms_mapping.c, and server/mms_mapping/mms_sv.c (via common/string_utilities.c), as demonstrated by iec61850_9_2_LE_example.c.
Published 2019-01-11 · Modified
7.5EPSS 0.015
CVE-2019-6719
An issue has been found in libIEC61850 v1.3.1. There is a use-after-free in the getState function in mms/iso_server/iso_server.c, as demonstrated by examples/server_example_goose/server_example_goose.c and examples/server_example_61400_25/server_example_61400_25.c.
Published 2019-01-23 · Modified
7.5EPSS 0.015
CVE-2019-16510
libIEC61850 through 1.3.3 has a use-after-free in MmsServer_waitReady in mms/iso_mms/server/mms_server.c, as demonstrated by server_example_goose.
Published 2019-09-19 · Modified
7.5EPSS 0.014
CVE-2019-1010300
mz-automation libiec61850 1.3.2 1.3.1 1.3.0 is affected by: Buffer Overflow. The impact is: Software crash. The component is: server_example_complex_array. The attack vector is: Send a specific MMS protocol packet.
Published 2019-07-15 · Modified
7.5EPSS 0.013
CVE-2022-1302
Malformed Goose Message in LibIEC61850 may result in a denial of service
Published 2022-04-12 · Modified
7.5EPSS 0.011
CVE-2021-45769
A NULL pointer dereference in AcseConnection_parseMessage at src/mms/iso_acse/acse.c of libiec61850 v1.5.0 can lead to a segmentation fault or application crash.
Published 2022-01-14 · Modified
7.5EPSS 0.011
CVE-2023-27772
libiec61850 v1.5.1 was discovered to contain a segmentation violation via the function ControlObjectClient_setOrigin() at /client/client_control.c.
Published 2023-04-13 · Modified
7.5EPSS 0.009
CVE-2024-26529
An issue in mz-automation libiec61850 v.1.5.3 and before, allows a remote attacker to cause a denial of service (DoS) via the mmsServer_handleDeleteNamedVariableListRequest function of src/mms/iso_mms/server/mms_named_variable_list_service.c.
Published 2024-03-13 · Analyzed
7.5EPSS 0.008
CVE-2024-28286
In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c function of src/mms/iso_mms/server/mms_file_service.c. The vulnerability manifests as SEGV and causes the application to crash
Published 2024-03-20 · Analyzed
7.5EPSS 0.007
CVE-2024-36702
libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c.
Published 2024-06-11 · Modified
7.4EPSS 0.002
CVE-2019-19930
In libIEC61850 1.4.0, MmsValue_newOctetString in mms/iso_mms/common/mms_value.c has an integer signedness error that can lead to an attempted excessive memory allocation.
Published 2019-12-23 · Modified
6.5EPSS 0.011
CVE-2019-19944
In libIEC61850 1.4.0, BerDecoder_decodeUint32 in mms/asn1/ber_decode.c has an out-of-bounds read, related to intLen and bufPos.
Published 2019-12-23 · Modified
6.5EPSS 0.009
CVE-2019-19957
In libIEC61850 1.4.0, getNumberOfElements in mms/iso_mms/server/mms_access_result.c has an out-of-bounds read vulnerability, related to bufPos and elementLength.
Published 2019-12-24 · Modified
6.5EPSS 0.009
CVE-2019-19958
In libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue that could lead to an attempted excessive memory allocation and denial of service.
Published 2019-12-24 · Modified
6.5EPSS 0.009
CVE-2024-25366
Buffer Overflow vulnerability in mz-automation.de libiec61859 v.1.4.0 allows a remote attacker to cause a denial of service via the mmsServer_handleGetNameListRequest function to the mms_getnamelist_service component.
Published 2024-02-20 · Analyzed
6.2EPSS 0.009
CVE-2018-19122
An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in Ethernet_sendPacket in ethernet_bsd.c.
Published 2018-11-09 · Modified
4.3EPSS 0.012
CVE-2018-19121
An issue has been found in libIEC61850 v1.3. It is a SEGV in Ethernet_receivePacket in ethernet_bsd.c.
Published 2018-11-09 · Modified
4.3EPSS 0.012