news.mlab.sh
Back to the feed
vulnerability

MZ Automation libIEC61850

High
Summary

MZ Automation libIEC61850 versions 1.0.0 through 1.6.1 are vulnerable to several stack and heap-based buffer overflows, potentially allowing an unauthenticated attacker to crash critical IEC 61850 services or execute arbitrary code. This impacts critical infrastructure sectors like manufacturing, energy, and transportation. The vendor recommends updating to the latest build to address these issues.

MZ Automation libIEC61850, a component used in industrial control systems, has been identified as containing multiple vulnerabilities. Specifically, the product is susceptible to stack-based buffer overflows (CWE-121) and heap-based buffer overflows (CWE-122) through crafted requests. A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser can lead to application crashes when a malformed GOOSE frame is sent. Similarly, a NULL pointer dereference in the MMS Write Named Variable List handler can cause a server crash when an empty `listOfData` field is included in a `WriteRequest`. These vulnerabilities could be exploited by an unauthenticated attacker to disrupt or compromise protection, visibility, and control functions within industrial control systems. The vendor, MZ Automation GmbH, recommends updating to the latest build of libIEC61850 to mitigate these risks. CISA advises organizations to minimize network exposure for control system devices, isolate them from business networks, and use secure remote access methods like VPNs, recognizing that VPNs themselves can have vulnerabilities. CISA also encourages organizations to perform impact analysis and risk assessments and implement proactive cybersecurity strategies for industrial control systems assets. No public exploitation specifically targeting these vulnerabilities has been reported at this time.

Read the full article at CISA Advisories