CVE-2019-19957: Medium severity mz automation libiec61850 vulnerability
In libIEC61850 1.4.0, getNumberOfElements in mms/isomms/server/mmsaccessresult.c has an out-of-bounds read vulnerability, related to bufPos and elementLength.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19957?
CVE-2019-19957 is classified as a moderate severity vulnerability due to the potential for out-of-bounds read exploitation.
How do I fix CVE-2019-19957?
To address CVE-2019-19957, update to a patched version of libIEC61850 that resolves the out-of-bounds read issue.
What software is affected by CVE-2019-19957?
CVE-2019-19957 specifically affects version 1.4.0 of the libIEC61850 software package created by MZ Automation.
What causes CVE-2019-19957?
CVE-2019-19957 is caused by an out-of-bounds read vulnerability in the getNumberOfElements function in the libIEC61850 library.
Can CVE-2019-19957 be exploited remotely?
Yes, CVE-2019-19957 can potentially be exploited remotely if an attacker can interact with the affected libIEC61850 component.