Mz-automation
Mz-automation Libiec61850: vulnerabilidades y CVE
Mz-automation Libiec61850 tiene 41 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE41
Últimos 12 meses6
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-19259 | Baja (1.9) | 0.17% | — | 8 ago 2026 | A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping_varAccessSpecToObjectReference of the file src/iec61850/common/iec61850_common.c of the component… |
| CVE-2026-19206 | Baja (1.9) | 0.17% | — | 7 ago 2026 | A security flaw has been discovered in MZ Automation libiec61850 up to 1.6.1. This affects the function SVReceiver_stopThreadless of the file src/sampled_values/sv_subscriber.c of the component ASDU Element Handler.… |
| CVE-2026-19108 | Baja (1.9) | 0.16% | — | 6 ago 2026 | A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file src/iec61850/server/mms_mapping/reporting.c of the component URCB… |
| CVE-2026-18583 | Media (5.5) | 0.86% | — | 3 ago 2026 | A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping.c of the component MMS Request Handler.… |
| CVE-2026-18582 | Media (5.5) | 0.86% | — | 3 ago 2026 | A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Reporting_RCBWriteAccessHandler of the file src/iec61850/server/mms_mapping/reporting.c of the… |
| CVE-2026-52134 | Crítica (9.8) | 0.80% | — | 31 jul 2026 | An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame. |
| CVE-2024-45971 | Crítica (9.8) | 0.61% | — | 15 nov 2024 | Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0 allow a malicious server to cause a stack-based buffer overflow via the MMS… |
| CVE-2024-45970 | Crítica (9.8) | 0.61% | — | 15 nov 2024 | Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via the MMS FileDirResponse… |
| CVE-2024-36702 | Alta (7.4) | 0.25% | — | 11 jun 2024 | libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c. |
| CVE-2024-28286 | Alta (7.5) | 0.74% | — | 21 mar 2024 | In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c function of src/mms/iso_mms/server/mms_file_service.c. The vulnerability manifests as SEGV and… |
| CVE-2024-26529 | Alta (7.5) | 0.78% | — | 13 mar 2024 | An issue in mz-automation libiec61850 v.1.5.3 and before, allows a remote attacker to cause a denial of service (DoS) via the mmsServer_handleDeleteNamedVariableListRequest function of… |
| CVE-2024-25366 | Media (6.2) | 0.87% | — | 20 feb 2024 | Buffer Overflow vulnerability in mz-automation.de libiec61859 v.1.4.0 allows a remote attacker to cause a denial of service via the mmsServer_handleGetNameListRequest function to the mms_getnamelist_service component. |
| CVE-2023-27772 | Alta (7.5) | 0.91% | — | 13 abr 2023 | libiec61850 v1.5.1 was discovered to contain a segmentation violation via the function ControlObjectClient_setOrigin() at /client/client_control.c. |
| CVE-2022-3976 | Alta (8.8) | 0.49% | — | 13 nov 2022 | A vulnerability has been found in MZ Automation libiec61850 up to 1.4 and classified as critical. This vulnerability affects unknown code of the file src/mms/iso_mms/client/mms_client_files.c of the component MMS File… |
| CVE-2022-2973 | Alta (7.5) | 1.1% | — | 23 sept 2022 | MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) uses a NULL pointer in certain situations. which could allow an attacker to crash the server. |
| CVE-2022-2972 | Crítica (9.8) | 1.6% | — | 23 sept 2022 | MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) is vulnerable to a stack-based buffer overflow, which could allow an attacker to crash the… |
| CVE-2022-2971 | Alta (7.5) | 1.1% | — | 23 sept 2022 | MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) accesses a resource using an incompatible type, which could allow an attacker to crash the… |
| CVE-2022-2970 | Crítica (9.8) | 1.5% | — | 23 sept 2022 | MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) does not sanitize input before memcpy is used, which could allow an attacker to crash the device… |
| CVE-2022-21159 | Alta (7.5) | 1.8% | — | 15 abr 2022 | A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec61850 1.5.0. A specially-crafted series of network requests can lead to denial of service. An attacker… |
| CVE-2022-1302 | Alta (7.5) | 1.1% | — | 12 abr 2022 | In the MZ Automation LibIEC61850 in versions prior to 1.5.1 an unauthenticated attacker can craft a goose message, which may result in a denial of service. |
| CVE-2021-45769 | Alta (7.5) | 1.1% | — | 14 ene 2022 | A NULL pointer dereference in AcseConnection_parseMessage at src/mms/iso_acse/acse.c of libiec61850 v1.5.0 can lead to a segmentation fault or application crash. |
| CVE-2020-15158 | Crítica (9.8) | 2.0% | — | 26 ago 2020 | In libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer underflow will happen leading to heap buffer overflow. This can cause an application crash or on… |
| CVE-2020-7054 | Alta (8.8) | 1.1% | — | 14 ene 2020 | MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c in libIEC61850 through 1.4.0 has a heap-based buffer overflow when parsing the MMS_BIT_STRING data type. |
| CVE-2019-19958 | Media (6.5) | 0.94% | — | 24 dic 2019 | In libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue that could lead to an attempted excessive memory allocation and denial of service. |
| CVE-2019-19957 | Media (6.5) | 0.94% | — | 24 dic 2019 | In libIEC61850 1.4.0, getNumberOfElements in mms/iso_mms/server/mms_access_result.c has an out-of-bounds read vulnerability, related to bufPos and elementLength. |
| CVE-2019-19944 | Media (6.5) | 0.94% | — | 23 dic 2019 | In libIEC61850 1.4.0, BerDecoder_decodeUint32 in mms/asn1/ber_decode.c has an out-of-bounds read, related to intLen and bufPos. |
| CVE-2019-19931 | Alta (8.8) | 1.3% | — | 23 dic 2019 | In libIEC61850 1.4.0, MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c has a heap-based buffer overflow. |
| CVE-2019-19930 | Media (6.5) | 1.1% | — | 23 dic 2019 | In libIEC61850 1.4.0, MmsValue_newOctetString in mms/iso_mms/common/mms_value.c has an integer signedness error that can lead to an attempted excessive memory allocation. |
| CVE-2019-16510 | Alta (7.5) | 1.4% | — | 19 sept 2019 | libIEC61850 through 1.3.3 has a use-after-free in MmsServer_waitReady in mms/iso_mms/server/mms_server.c, as demonstrated by server_example_goose. |
| CVE-2019-1010300 | Alta (7.5) | 1.3% | — | 15 jul 2019 | mz-automation libiec61850 1.3.2 1.3.1 1.3.0 is affected by: Buffer Overflow. The impact is: Software crash. The component is: server_example_complex_array. The attack vector is: Send a specific MMS protocol packet. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.