Critical severity10.0NVD Advisory· Published Sep 23, 2022· Updated Jun 17, 2026
CVE-2022-2970
CVE-2022-2970
Description
MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) does not sanitize input before memcpy is used, which could allow an attacker to crash the device or remotely execute arbitrary code.
Affected products
3cpe:2.3:a:mz-automation:libiec61850:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mz-automation:libiec61850:*:*:*:*:*:*:*:*range: <1.5.0
- (no CPE)range: <=1.4, <1.5
- (no CPE)range: All
Patches
Vulnerability mechanics
References
1- www.cisa.gov/uscert/ics/advisories/icsa-22-251-01nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.