CVE-2020-7054: Buffer Overflow
Published Jan 14, 2020
·Updated
MmsValuedecodeMmsData in mms/isomms/server/mmsaccessresult.c in libIEC61850 through 1.4.0 has a heap-based buffer overflow when parsing the MMSBITSTRING data type.
Affected Software
1 affected component
mz-automation libiec61850<=1.4.0
Event History
Jan 14, 2020
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-7054?
CVE-2020-7054 is classified as a high severity vulnerability due to its potential for causing a heap-based buffer overflow.
2
What software versions are affected by CVE-2020-7054?
CVE-2020-7054 affects all versions of libIEC61850 up to and including version 1.4.0.
3
How do I fix CVE-2020-7054?
To fix CVE-2020-7054, upgrade to a version of libIEC61850 that is newer than 1.4.0.
4
What type of vulnerability is CVE-2020-7054?
CVE-2020-7054 is a heap-based buffer overflow vulnerability that occurs when parsing MMS_BIT_STRING data.
5
Can CVE-2020-7054 be exploited remotely?
Yes, CVE-2020-7054 can potentially be exploited remotely under certain conditions involving MMS_BIT_STRING data.