A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec61850 1.5.0. A specially-crafted series of network requests can lead to denial of service. An attacker can send a sequence of malformed iec61850 messages to trigger this vulnerability.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1467 | third party advisory exploit |
https://github.com/mz-automation/libiec61850/commit/cfa94cbf10302bedc779703f874ee2e8387a0721 | third party advisory patch |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1467 | third party advisory exploit |