CVE-2022-2972: MZ Automation libIEC61850 Stack-Based Buffer Overflow
MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) is vulnerable to a stack-based buffer overflow, which could allow an attacker to crash the device or remotely execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2972?
CVE-2022-2972 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2022-2972?
To fix CVE-2022-2972, upgrade to version 1.5.0 or later of MZ Automation's libIEC61850.
What causes the CVE-2022-2972 vulnerability?
CVE-2022-2972 is caused by a stack-based buffer overflow in libIEC61850 versions 1.4 and prior.
What are the potential impacts of CVE-2022-2972?
The impacts of CVE-2022-2972 include device crashes and the possibility of remote arbitrary code execution.
Which versions of libIEC61850 are affected by CVE-2022-2972?
CVE-2022-2972 affects libIEC61850 versions 1.4 and prior, as well as version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e.