Out-of-Bounds Read in libIEC61850 Affects Software by MZ Automation
CVE-2019-19944
6.5MEDIUM
What is CVE-2019-19944?
In libIEC61850 version 1.4.0, an out-of-bounds read vulnerability exists in the BerDecoder_decodeUint32 function found in mms/asn1/ber_decode.c. This issue is associated with improper handling of the intLen and bufPos parameters, which can lead to unintended access to memory outside the expected bounds. Exploitation of this vulnerability may allow attackers to read sensitive information, potentially impacting the integrity and confidentiality of the data processed by the affected software.
