MZ Automation GmbH libiec61850
Summary
Multiple vulnerabilities have been identified in MZ Automation GmbH's libiec61850 software, specifically affecting versions prior to 1.6.2. Exploitation of these vulnerabilities could lead to a denial-of-service condition on affected devices. The vulnerabilities involve improper validation of timestamp fields in IEC 61850 GOOSE messages, potentially causing heap out-of-bounds reads.
IFF Assessment
These vulnerabilities allow attackers to cause denial-of-service conditions, disrupting critical infrastructure operations.
Severity
The CVSS v3.1 score of 6.5 (MEDIUM) is based on an Attack Vector of Adjacent (AV:A), Low Attack Complexity (AC:L), No Privileges Required (PR:N), No User Interaction (UI:N), and Unchanged Scope (S:U), with a High impact on Availability (A:H) but no impact on Confidentiality (C:N) or Integrity (I:N). The specific vulnerability detailed involves an out-of-bounds read due to improper timestamp validation.
Defender Context
Defenders in the energy sector should prioritize patching or updating MZ Automation GmbH's libiec61850 to version 1.6.2 or later to mitigate the risk of denial-of-service attacks. The vulnerabilities exploit improper handling of IEC 61850 GOOSE messages, highlighting the need for robust input validation and secure coding practices in Industrial Control System (ICS) software.