VendorsMZ-Automationlibiec61850any version
Vulnerabilities

MZ-Automation libIEC61850 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2022-2972
MZ Automation libIEC61850 Stack-Based Buffer Overflow
Published 2022-09-23 · Modified
10.0EPSS 0.016
CVE-2022-2970
MZ Automation libIEC61850 Stack-Based Buffer Overflow
Published 2022-09-23 · Modified
10.0EPSS 0.015
CVE-2020-15158
Heap buffer overflow in libIEC61850
Published 2020-08-26 · Modified
9.8EPSS 0.020
CVE-2024-45970
Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via the MMS FileDirResponse message.
Published 2024-11-15 · Analyzed
9.8EPSS 0.006
CVE-2024-45971
Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0 allow a malicious server to cause a stack-based buffer overflow via the MMS IdentifyResponse message.
Published 2024-11-15 · Analyzed
9.8EPSS 0.006
CVE-2020-7054
MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c in libIEC61850 through 1.4.0 has a heap-based buffer overflow when parsing the MMS_BIT_STRING data type.
Published 2020-01-14 · Modified
8.8EPSS 0.011
CVE-2022-3976
MZ Automation libiec61850 MMS File Services mms_client_files.c path traversal
Published 2022-11-13 · Modified
8.8EPSS 0.005
CVE-2022-2971
MZ Automation libIEC61850 Access of Resource Using Incompatible Type ('Type Confusion')
Published 2022-09-23 · Modified
8.6EPSS 0.011
CVE-2022-2973
MZ Automation libIEC61850 NULL Pointer Dereference
Published 2022-09-23 · Modified
8.6EPSS 0.011
CVE-2019-16510
libIEC61850 through 1.3.3 has a use-after-free in MmsServer_waitReady in mms/iso_mms/server/mms_server.c, as demonstrated by server_example_goose.
Published 2019-09-19 · Modified
7.5EPSS 0.014
CVE-2022-1302
Malformed Goose Message in LibIEC61850 may result in a denial of service
Published 2022-04-12 · Modified
7.5EPSS 0.011
CVE-2024-26529
An issue in mz-automation libiec61850 v.1.5.3 and before, allows a remote attacker to cause a denial of service (DoS) via the mmsServer_handleDeleteNamedVariableListRequest function of src/mms/iso_mms/server/mms_named_variable_list_service.c.
Published 2024-03-13 · Analyzed
7.5EPSS 0.008