CVE-2020-15158 is a critical heap buffer overflow vulnerability affecting mz-automation libIEC61850 versions prior to 1.4.3. This flaw occurs when a crafted COTP message with a length field value less than 4 triggers an integer underflow, leading to a heap buffer overflow. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with low attack complexity and no user interaction, potentially resulting in application crashes or remote code execution. While no public exploits or active exploitation have been observed, and community discussion is minimal, the severe impact necessitates immediate patching to version 1.4.3 or applying the specified commit as a workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.4.0, < 1.4.3CPE matchmatch criteria | cpe:2.3:a:mz-automation:libiec61850:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.