Buffer Overflow Vulnerability in libiec61850 by mz-automation
CVE-2024-25366

6.2MEDIUM

Key Information:

Vendor
CVE Published:
20 February 2024

What is CVE-2024-25366?

A buffer overflow vulnerability exists in version 1.4.0 of mz-automation's libiec61850, specifically within the mmsServer_handleGetNameListRequest function. This vulnerability can be exploited remotely, leading to a potential denial of service condition, affecting the operation of the mms_getnamelist_service component.

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.