CVE-2022-38138: High severity triangle microworks tmw library: iec 60870-6 (iccp/tase.2) vulnerability
The Triangle Microworks IEC 61850 Library (Any client or server using the C language library with a version number of 11.2.0 or earlier and any client or server using the C++, C#, or Java language library with a version number of 5.0.1 or earlier) and 60870-6 (ICCP/TASE.2) Library (Any client or server using a C++ language library with a version number of 4.4.3 or earlier) are vulnerable to access given to a small number of uninitialized pointers within their code. This could allow an attacker to target any client or server using the affected libraries to cause a denial-of-service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-38138?
CVE-2022-38138 has a high severity rating, which indicates significant risk to affected systems.
How do I fix CVE-2022-38138?
To remediate CVE-2022-38138, upgrade to the latest version of the Triangle Microworks libraries that are not affected by this vulnerability.
Which Triangle Microworks products are affected by CVE-2022-38138?
CVE-2022-38138 affects the Triangle Microworks IEC 61850 Library version 11.2.0 and earlier, and IEC 60870-6 Library version 4.4.3 and earlier.
What types of attacks can CVE-2022-38138 facilitate?
CVE-2022-38138 can be exploited by attackers to compromise data integrity or lead to unauthorized access to systems using the affected libraries.
Is there a workaround for CVE-2022-38138 while waiting for a patch?
Currently, there are no official workarounds for CVE-2022-38138; the best approach is to upgrade to a secure version of the libraries.