Heap Buffer Overflow in libIEC61850 Affects Multiple Versions
CVE-2020-7054

8.8HIGH

Key Information:

Vendor
CVE Published:
14 January 2020

What is CVE-2020-7054?

The vulnerability is a heap-based buffer overflow found in the mmsValue_decodeMmsData function located in the mms_access_result.c file of libIEC61850. This issue arises when the library processes the MMS_BIT_STRING data type, leading to potential memory corruption. Versions up to and including 1.4.0 are affected, allowing for unintended behavior that could be exploited by attackers to compromise system integrity.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.