Heap-Based Buffer Overflow in libIEC61850 Affecting Automation Systems
CVE-2018-19185

9.8CRITICAL

Key Information:

Vendor
CVE Published:
12 November 2018

What is CVE-2018-19185?

A vulnerability exists in libIEC61850 v1.3 that results in a heap-based buffer overflow in the BerEncoder_encodeOctetString function. This issue can be exploited independently of a previous patch, specifically utilizing a different dataSetValue sequence than that identified in earlier vulnerabilities. Consequently, this presents significant risks to the security of automation systems relying on this library, necessitating immediate attention and remediation.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.