yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-45970
Component Overview
Vulnerability Overview
Name
CVE-2024-45970
Source
NVD (
link
)
Debian (
link
)
Description
Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via the MMS FileDirResponse message.
CWEs
CWE-120
Published Date
Nov 15, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://encs.eu/news/critical-security-vulnerabilities-discovered-in-mz-automations-mms-client/
Third Party Advisory
https://github.com/mz-automation/libiec61850/commit/ac925fae8e281ac6defcd630e9dd756264e9c5bc
Patch
Analysis
#
Affected Component
Analysis
libiec61850
Exploitable
Vulnerability Ratings
#
9.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libiec61850
buildroot
2025.02.x
1.6.0
Not Affected
libiec61850
buildroot
master
1.6.1
Not Affected
libiec61850
yocto
master
1.6.1
Not Affected
libiec61850
yocto
scarthgap
1.5.3
Exploitable