PT-2024-31864 · Mz Automation · Libiec61850
Albert Spruyt
+1
·
Published
2024-11-15
·
Updated
2025-10-01
·
CVE-2024-45971
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MZ Automation LibIEC61850 versions before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0
Description
The issue is related to multiple buffer overflows in the MMS Client of MZ Automation LibIEC61850. A malicious server can cause a stack-based buffer overflow via the MMS IdentifyResponse message, potentially leading to remote code execution and system compromise.
Recommendations
For versions before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0, update to a version that includes the fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the MMS Client to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libiec61850