PT-2022-4741 · Mz Automation+1 · Libiec61850+1

Vera Mens

·

Published

2021-09-23

·

Updated

2024-08-19

·

CVE-2022-2971

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MZ Automation's libIEC61850 versions 1.4 and prior MZ Automation's libIEC61850 version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e
Description The issue is related to accessing a resource using an incompatible type, which could allow an attacker to crash the server with a malicious payload. This could potentially lead to a denial of service.
Recommendations For MZ Automation's libIEC61850 versions 1.4 and prior, update to a version later than 1.4. For MZ Automation's libIEC61850 version 1.5, apply the changes from commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e or later. As a temporary workaround, consider restricting access to the server to minimize the risk of exploitation.

Fix

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2864
ALT-PU-2024-11160
BDU:2022-05637
CVE-2022-2971

Affected Products

Alt Linux
Libiec61850