漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
MZ Automation libiec61850 Out-of-bounds Read
Vulnerability Description
The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
跨界内存读
Vulnerability Title
MZ Automation GmbH libiec61850 缓冲区错误漏洞
Vulnerability Description
MZ Automation GmbH libiec61850是德国MZ Automation GmbH公司开源的一套支持IEC 61850标准的工业通信组件。 MZ Automation GmbH libiec61850 1.6.2之前版本存在缓冲区错误漏洞,该漏洞源于ACSE层在处理MMS连接建立期间的AARQ PDU时,对调用AP标题中攻击者控制的长度值(零或一)验证不当,导致解析器越界读取堆缓冲区,可能造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A