Use-After-Free Vulnerability in libIEC61850 Affecting MmsServer
CVE-2019-16510

7.5HIGH

Key Information:

Vendor
CVE Published:
19 September 2019

What is CVE-2019-16510?

libIEC61850 version 1.3.3 contains a use-after-free vulnerability in the MmsServer_waitReady function located in the mms_server.c file. This flaw can be exploited to cause unintended behavior or crashes in applications that utilize this library, thereby potentially compromising system integrity. The vulnerability was demonstrated using the server_example_goose functionality.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.