Out-of-Bounds Read in libIEC61850 Affects Software by MZ Automation
CVE-2019-19944

6.5MEDIUM

Key Information:

Vendor
CVE Published:
23 December 2019

What is CVE-2019-19944?

In libIEC61850 version 1.4.0, an out-of-bounds read vulnerability exists in the BerDecoder_decodeUint32 function found in mms/asn1/ber_decode.c. This issue is associated with improper handling of the intLen and bufPos parameters, which can lead to unintended access to memory outside the expected bounds. Exploitation of this vulnerability may allow attackers to read sensitive information, potentially impacting the integrity and confidentiality of the data processed by the affected software.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.