ICSA-22-249-01: Triangle microworks tmw library: iec 61850 any client or server using the c language library with a version number of 11.2.0 or earlier. any client or server using the c++, c#, or java language library with a version number of 5.0.1 or earlier vulnerability
Affected Software
5 affected components
Triangle MicroWorks TMW Library: IEC 61850
Any client or server using the C language library with a version number of 11.2.0 or earlier.
Any client or server using the C++, C#, or Java language library with a version number of 5.0.1 or earlier
Triangle MicroWorks Any client or server using the C language library with a version number of 11.2.0 or earlier
Triangle MicroWorks Any client or server using the C++, C#, or Java language library with a version number of 5.0.1 or earlier
Triangle MicroWorks TMW Library: IEC 60870-6 (ICCP/Tase.2)
Any client or server using a C++ language library with a version number of 4.4.3 or earlier
Triangle MicroWorks Any client or server using a C++ language library with a version number of 4.4.3 or earlier
Event History
Feb 24, 2025
Advisory Published
09:38 AM
Frequently Asked Questions
1
What is the severity of ICSA-22-249-01?
The severity of ICSA-22-249-01 is considered high due to the potential for unauthorized access to critical systems.
2
How do I fix ICSA-22-249-01?
To fix ICSA-22-249-01, update the Triangle MicroWorks TMW Library to the latest versions: 11.2.1 for C language and 5.0.2 for C++, C#, or Java.
3
What systems are affected by ICSA-22-249-01?
ICSA-22-249-01 affects any client or server using Triangle MicroWorks TMW Library versions prior to 11.2.1 for C and 5.0.2 for C++, C#, or Java.
4
Has a proof of concept been released for ICSA-22-249-01?
Yes, a proof of concept for exploiting ICSA-22-249-01 has been reported, escalating the urgency for patching.
5
What should organizations do to mitigate risks from ICSA-22-249-01?
Organizations should immediately assess their systems for vulnerable library versions and apply the necessary updates to mitigate risks from ICSA-22-249-01.