PT-2024-31864 · Mz Automation · Libiec61850

Albert Spruyt

+1

·

Published

2024-11-15

·

Updated

2025-10-01

·

CVE-2024-45971

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MZ Automation LibIEC61850 versions before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0
Description The issue is related to multiple buffer overflows in the MMS Client of MZ Automation LibIEC61850. A malicious server can cause a stack-based buffer overflow via the MMS IdentifyResponse message, potentially leading to remote code execution and system compromise.
Recommendations For versions before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0, update to a version that includes the fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the MMS Client to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-45971

Affected Products

Libiec61850