As cited
Copy frozen at (site build).
vulnerabilities
MZ Automation GmbH libiec61850
MZ Automation GmbH libiec61850 versions prior to 1.6.2 contain eight out-of-bounds read vulnerabilities affecting the GOOSE subscriber and MMS (Manufacturing Message Specification) BER decoder components. These flaws allow unauthenticated attackers on the local network or authenticated users to craft specially formatted messages that crash the affected processes, resulting in denial-of-service conditions. The vendor recommends immediate updates to version 1.6.2 to remediate the issues.
Why it matters: Energy infrastructure operators and power systems integrators relying on libiec61850 for IEC 61850 GOOSE and MMS communications face process crashes and loss of control messaging from low-complexity network attacks, potentially disrupting real-time coordination on process buses worldwide.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
MZ Automation GmbH libiec61850
MZ Automation GmbH libiec61850 versions prior to 1.6.2 contain eight out-of-bounds read vulnerabilities affecting the GOOSE subscriber and MMS (Manufacturing Message Specification) BER decoder components. These flaws allow unauthenticated attackers on the local network or authenticated users to craft specially formatted messages that crash the affected processes, resulting in denial-of-service conditions. The vendor recommends immediate updates to version 1.6.2 to remediate the issues.
Why it matters: Energy infrastructure operators and power systems integrators relying on libiec61850 for IEC 61850 GOOSE and MMS communications face process crashes and loss of control messaging from low-complexity network attacks, potentially disrupting real-time coordination on process buses worldwide.
- Source published
- First seen by Cybersecurity Tracker