CVE-2022-2971: MZ Automation libIEC61850 Access of Resource Using Incompatible Type ('Type Confusion')
MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) accesses a resource using an incompatible type, which could allow an attacker to crash the server with a malicious payload.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2971?
CVE-2022-2971 is a vulnerability in MZ Automation's libIEC61850 software that allows an attacker to crash the server with a malicious payload.
What versions of libIEC61850 are affected by CVE-2022-2971?
Versions 1.4 and prior, as well as version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e, are affected.
How severe is CVE-2022-2971?
CVE-2022-2971 has a severity rating of 7.5, which is considered high.
How can an attacker exploit CVE-2022-2971?
An attacker can exploit CVE-2022-2971 by accessing a resource using an incompatible type, which crashes the server with a malicious payload.
Is there a fix for CVE-2022-2971?
At the moment, there is no specific fix available for CVE-2022-2971. It is recommended to follow the guidance provided by MZ Automation and stay updated with any patches or security updates.