CVE-2022-2970

CRITICAL

libiec61850 < 1.5.0 - Stack-based Buffer Overflow via Unsanitized Input to memcpy

Title source: llm
STIX 2.1

Description

MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) does not sanitize input before memcpy is used, which could allow an attacker to crash the device or remotely execute arbitrary code.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsa-22-251-01

Scores

CVSS v3 10.0
EPSS 0.0106
EPSS Percentile 60.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-121 CWE-787
Status published
Products (1)
mz-automation/libiec61850 < 1.5.0
Published Sep 23, 2022
Tracked Since Feb 18, 2026