Executive brief
MZ Automation libiec61850 is a library used by industrial control system (ICS) client applications to communicate with power grid and utility servers using the IEC 61850 protocol. A malicious or compromised server can send a specially crafted response that triggers a heap buffer overflow in the client, causing the application to crash and denying service to operators who rely on these systems for monitoring and control.
Technical details
The vulnerability is a heap buffer over-read in the MmsMapping_varAccessSpecToObjectReference function (src/iec61850/common/iec61850_common.c, line 876) triggered by a malformed GetNamedVariableListAttributesResponse.itemId field. The vulnerable code assumes that decoded MMS names follow an internal LN$FC$... format and performs fixed-offset reads relative to the first '