CVE-2024-36702: High severity libiec61850 libiec61850 vulnerability
Published Jun 11, 2024
·Updated
libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoderencodeLength function at /asn1/berencoder.c.
Affected Software
2 affected components
libiec61850 libiec61850
mz-automation libiec61850=1.5
Event History
Jun 11, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-36702?
CVE-2024-36702 has been classified as a critical vulnerability due to the potential for remote code execution from a heap overflow.
2
How do I fix CVE-2024-36702?
To fix CVE-2024-36702, users should upgrade to libiec61850 version 1.5 or later where the vulnerability is patched.
3
What is affected by CVE-2024-36702?
CVE-2024-36702 affects libiec61850 version 1.5, which is commonly used in industrial communication systems.
4
What is the cause of CVE-2024-36702?
CVE-2024-36702 is caused by a heap overflow vulnerability in the BerEncoder_encodeLength function in the asn1/ber_encoder.c file.
5
Can CVE-2024-36702 be exploited remotely?
Yes, CVE-2024-36702 can be exploited remotely, making it a serious threat if not mitigated promptly.