yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2024-45971
Component Overview
Vulnerability Overview
Name
CVE-2024-45971
Source
NVD (
link
)
Debian (
link
)
Description
Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0 allow a malicious server to cause a stack-based buffer overflow via the MMS IdentifyResponse message.
CWEs
CWE-120
Published Date
Nov 15, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://encs.eu/news/critical-security-vulnerabilities-discovered-in-mz-automations-mms-client/
Third Party Advisory
https://github.com/mz-automation/libiec61850/commit/1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0
Patch
Analysis
#
Affected Component
Analysis
libiec61850
Exploitable
Vulnerability Ratings
#
9.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libiec61850
buildroot
2025.02.x
1.6.0
Not Affected
libiec61850
buildroot
master
1.6.1
Not Affected
libiec61850
yocto
kirkstone
1.5.1
Exploitable
libiec61850
yocto
master
1.6.1
Not Affected