Segmentation Fault in libIEC61850 Client Control Implementation by mz-automation
CVE-2018-19093

7.5HIGH

Key Information:

Vendor
CVE Published:
7 November 2018

What is CVE-2018-19093?

An issue has been identified in libIEC61850 v1.3 that leads to a segmentation fault when utilizing the ControlObjectClient_setCommandTerminationHandler function. This vulnerability occurs due to improper usage of the client_example_control program. Although the software maintainer has raised concerns about the legitimacy of this issue, it reveals the need for caution when implementing control commands in the client application.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.