PT-2022-4741 · Mz Automation+1 · Libiec61850+1
Vera Mens
·
Published
2021-09-23
·
Updated
2024-08-19
·
CVE-2022-2971
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MZ Automation's libIEC61850 versions 1.4 and prior
MZ Automation's libIEC61850 version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e
Description
The issue is related to accessing a resource using an incompatible type, which could allow an attacker to crash the server with a malicious payload. This could potentially lead to a denial of service.
Recommendations
For MZ Automation's libIEC61850 versions 1.4 and prior, update to a version later than 1.4.
For MZ Automation's libIEC61850 version 1.5, apply the changes from commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e or later.
As a temporary workaround, consider restricting access to the server to minimize the risk of exploitation.
Fix
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Libiec61850