Vulnerabilities > MZ Automation > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-02-24 | CVE-2023-23205 | Memory Leak vulnerability in Mz-Automation Lib60870 2.3.2 An issue was discovered in lib60870 v2.3.2. | 5.5 |
2022-04-15 | CVE-2022-21159 | Infinite Loop vulnerability in Mz-Automation Libiec61850 1.5.0 A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec61850 1.5.0. | 5.0 |
2022-04-12 | CVE-2022-1302 | Unspecified vulnerability in Mz-Automation Libiec61850 In the MZ Automation LibIEC61850 in versions prior to 1.5.1 an unauthenticated attacker can craft a goose message, which may result in a denial of service. | 5.0 |
2022-01-14 | CVE-2021-45769 | NULL Pointer Dereference vulnerability in Mz-Automation Libiec61850 1.5.0 A NULL pointer dereference in AcseConnection_parseMessage at src/mms/iso_acse/acse.c of libiec61850 v1.5.0 can lead to a segmentation fault or application crash. | 5.0 |
2022-01-14 | CVE-2021-45773 | NULL Pointer Dereference vulnerability in Mz-Automation Lib60870 A NULL pointer dereference in CS104_IPAddress_setFromString at src/iec60870/cs104/cs104_slave.c of lib60870 commit 0d5e76e can lead to a segmentation fault or application crash. | 5.0 |
2021-08-25 | CVE-2021-21778 | Reachable Assertion vulnerability in Mz-Automation Lib60870 2.2.0 A denial of service vulnerability exists in the ASDU message processing functionality of MZ Automation GmbH lib60870.NET 2.2.0. | 5.0 |
2020-01-14 | CVE-2020-7054 | Out-of-bounds Write vulnerability in Mz-Automation Libiec61850 MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c in libIEC61850 through 1.4.0 has a heap-based buffer overflow when parsing the MMS_BIT_STRING data type. | 6.8 |
2019-12-24 | CVE-2019-19958 | Allocation of Resources Without Limits or Throttling vulnerability in Mz-Automation Libiec61850 1.4.0 In libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue that could lead to an attempted excessive memory allocation and denial of service. | 4.3 |
2019-12-24 | CVE-2019-19957 | Out-of-bounds Read vulnerability in Mz-Automation Libiec61850 1.4.0 In libIEC61850 1.4.0, getNumberOfElements in mms/iso_mms/server/mms_access_result.c has an out-of-bounds read vulnerability, related to bufPos and elementLength. | 4.3 |
2019-12-23 | CVE-2019-19944 | Out-of-bounds Read vulnerability in Mz-Automation Libiec61850 1.4.0 In libIEC61850 1.4.0, BerDecoder_decodeUint32 in mms/asn1/ber_decode.c has an out-of-bounds read, related to intLen and bufPos. | 4.3 |