← Vulnerability feed

Vulnerability record · CVE-2024-45970 · published 15 November 2024

CVE-2024-45970: Mz-automation libiec61850 classic buffer overflow vulnerability

Mz Automation · Libiec61850

Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via the MMS FileDirResponse message.

9.8 CVSS 3.1 Critical EPSS 0.62% · top 52.7% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via the MMS FileDirResponse message.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-45970 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-45971Mz-automation libiec61850 classic buffer overflow vulnerabilityMultiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0 allow a malicious ser…EPSS 0.62%9.8CVE-2022-2970Mz-automation libiec61850 stack-based buffer overflow vulnerabilityMZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) does not sanitize input be…EPSS 1.5%9.8CVE-2022-2972Mz-automation libiec61850 stack-based buffer overflow vulnerabilityMZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) is vulnerable to a stack-b…EPSS 1.6%9.8CVE-2020-15158Mz-automation libiec61850 memory buffer overflow vulnerabilityIn libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer underflow will happen leadin…EPSS 2.0%9.8CVE-2018-19185Mz-automation libiec61850 out-of-bounds write vulnerabilityAn issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c. This is ex…EPSS 2.1%9.8CVE-2018-18957Mz-automation libiec61850 out-of-bounds write vulnerabilityAn issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c.EPSS 12%9.8CVE-2018-18834Mz-automation libiec61850 out-of-bounds write vulnerabilityAn issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c.EPSS 2.1%8.8CVE-2022-3976Mz-automation libiec61850 path traversal vulnerabilityA vulnerability has been found in MZ Automation libiec61850 up to 1.4 and classified as critical. This vulnerability affects unknown code of the file…EPSS 0.49%

Source: NIST National Vulnerability Database (record CVE-2024-45970), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.