Use-After-Free Vulnerability in libIEC61850 Affects Automation Products
CVE-2019-6719

7.5HIGH

Key Information:

Vendor
CVE Published:
23 January 2019

What is CVE-2019-6719?

In libIEC61850 version 1.3.1, a use-after-free vulnerability exists in the getState function found in the source file iso_server.c. This flaw can be exploited through crafted inputs, potentially leading to unexpected behavior or execution of arbitrary code. Various examples provided detail how this vulnerability manifests within server implementations, underscoring the risk for automation products utilizing this library.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.