Denial of Service Vulnerability in MZ Automation libiec61850
CVE-2022-21159
7.5HIGH
What is CVE-2022-21159?
A denial of service vulnerability has been identified in the parseNormalModeParameters function of MZ Automation GmbH's libiec61850 version 1.5.0. Attackers can exploit this vulnerability by sending a series of specially crafted IEC 61850 messages, which can overwhelm the application and lead to service disruption. The nature of the malformed requests can disrupt normal operations, making it critical for users to implement appropriate security measures to defend against such attacks.
Affected Version(s)
libiec61850 1.5.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
