VYPR

Libiec61850

by Mz Automation

Source repositories

CVEs (42)

  • CVE-2018-18937HigNov 5, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in ClientDataSet_getValues in client/ied_connection.c.

  • CVE-2024-36702HigJun 11, 2024
    risk 0.48cvss 7.4epss 0.00

    libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c.

  • CVE-2024-45969HigNov 15, 2024
    risk 0.42cvss 7.5epss 0.00

    NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e357ef33 allows a malicious server to Cause a Denial-of-Service via the MMS InitiationResponse message.

  • CVE-2019-19958MedDec 24, 2019
    risk 0.42cvss 6.5epss 0.01

    In libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue that could lead to an attempted excessive memory allocation and denial of service.

  • CVE-2019-19957MedDec 24, 2019
    risk 0.42cvss 6.5epss 0.01

    In libIEC61850 1.4.0, getNumberOfElements in mms/iso_mms/server/mms_access_result.c has an out-of-bounds read vulnerability, related to bufPos and elementLength.

  • CVE-2019-19944MedDec 23, 2019
    risk 0.42cvss 6.5epss 0.01

    In libIEC61850 1.4.0, BerDecoder_decodeUint32 in mms/asn1/ber_decode.c has an out-of-bounds read, related to intLen and bufPos.

  • CVE-2019-19930MedDec 23, 2019
    risk 0.42cvss 6.5epss 0.01

    In libIEC61850 1.4.0, MmsValue_newOctetString in mms/iso_mms/common/mms_value.c has an integer signedness error that can lead to an attempted excessive memory allocation.

  • CVE-2024-25366MedFeb 20, 2024
    risk 0.40cvss 6.2epss 0.01

    Buffer Overflow vulnerability in mz-automation.de libiec61859 v.1.4.0 allows a remote attacker to cause a denial of service via the mmsServer_handleGetNameListRequest function to the mms_getnamelist_service component.

  • CVE-2026-19108MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file src/iec61850/server/mms_mapping/reporting.c of the component URCB Revalidation. The manipulation results in use after free. The…

  • CVE-2018-19122MedNov 9, 2018
    risk 0.28cvss 4.3epss 0.01

    An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in Ethernet_sendPacket in ethernet_bsd.c.

  • CVE-2018-19121MedNov 9, 2018
    risk 0.28cvss 4.3epss 0.01

    An issue has been found in libIEC61850 v1.3. It is a SEGV in Ethernet_receivePacket in ethernet_bsd.c.

  • CVE-2026-19259MedAug 8, 2026
    risk 0.27cvss 5.3epss 0.00

    A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping_varAccessSpecToObjectReference of the file src/iec61850/common/iec61850_common.c of the component MMS Protocol Workflow. Such manipulation of the argument…

  • CVE-2026-19206MedAug 7, 2026
    risk 0.27cvss 5.3epss 0.00

    A security flaw has been discovered in MZ Automation libiec61850 up to 1.6.1. This affects the function SVReceiver_stopThreadless of the file src/sampled_values/sv_subscriber.c of the component ASDU Element Handler. Performing a manipulation results in heap-based buffer…

  • CVE-2026-18583MedAug 3, 2026
    risk 0.27cvss 5.3epss 0.01

    A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping.c of the component MMS Request Handler. This manipulation causes out-of-bounds read. The attack can…

  • CVE-2026-18582MedAug 3, 2026
    risk 0.27cvss 5.3epss 0.01

    A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Reporting_RCBWriteAccessHandler of the file src/iec61850/server/mms_mapping/reporting.c of the component Report Sending Path Handler. The manipulation results in…

  • CVE-2026-52134CriJul 31, 2026
    risk 0.00cvss 9.8epss 0.01

    An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.

  • CVE-2024-45971CriNov 15, 2024
    risk 0.00cvss 9.8epss 0.01

    Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0 allow a malicious server to cause a stack-based buffer overflow via the MMS IdentifyResponse message.

  • CVE-2024-45970CriNov 15, 2024
    risk 0.00cvss 9.8epss 0.01

    Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via the MMS FileDirResponse message.

  • CVE-2023-27772HigApr 13, 2023
    risk 0.00cvss 7.5epss 0.01

    libiec61850 v1.5.1 was discovered to contain a segmentation violation via the function ControlObjectClient_setOrigin() at /client/client_control.c.

  • CVE-2022-3976MedNov 13, 2022
    risk 0.00cvss 5.5epss 0.00

    A vulnerability has been found in MZ Automation libiec61850 up to 1.4 and classified as critical. This vulnerability affects unknown code of the file src/mms/iso_mms/client/mms_client_files.c of the component MMS File Services. The manipulation of the argument filename leads to…