Memory Leak in libIEC61850 Affects MZ Automation
CVE-2019-6135

7.5HIGH

Key Information:

Vendor
CVE Published:
11 January 2019

What is CVE-2019-6135?

A vulnerability in libIEC61850 version 1.3.1 has been identified, where a memory leak occurs in the memory allocation function located in hal/memory/lib_memory.c. This issue arises when the Asn1PrimitiveValue_create function, found in mms/asn1/asn1_ber_primitive_value.c, is invoked. The impact of this flaw can lead to excessive memory consumption, which if unaddressed, may cause performance degradation and potential system instability. Developers and users are encouraged to monitor the affected implementations and resolve this issue promptly.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.