Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. The resulting buffer overflow can cause a crash, resulting in a denial of service.
References
Link | Resource |
---|---|
https://trianglemicroworks.com/products/source-code-libraries/iec-61850-scl-pages/what%27s-new | Release Notes |
https://www.cisa.gov/news-events/ics-advisories/icsa-24-256-16 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
|
History
25 Sep 2024, 17:08
Type | Values Removed | Values Added |
---|---|---|
First Time |
Siemens sicam A8000 Firmware
Siemens Siemens sicam S8000 Siemens sicam Scc Firmware Trianglemicroworks Siemens sicam A8000 Siemens sicam Egs Firmware Trianglemicroworks iec 61850 Source Code Library Siemens sitipe At Siemens sicam Scc Siemens sicam Egs |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CPE | cpe:2.3:h:siemens:sicam_scc:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:sicam_a8000:-:*:*:*:*:*:*:* cpe:2.3:a:siemens:sitipe_at:*:*:*:*:*:*:*:* cpe:2.3:h:siemens:sicam_egs:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:sicam_egs_firmware:*:*:*:*:*:*:*:* cpe:2.3:a:trianglemicroworks:iec_61850_source_code_library:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:sicam_s8000:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:sicam_a8000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:sicam_scc_firmware:*:*:*:*:*:*:*:* |
|
References | () https://trianglemicroworks.com/products/source-code-libraries/iec-61850-scl-pages/what%27s-new - Release Notes | |
References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-256-16 - Third Party Advisory, US Government Resource |
19 Sep 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE | CWE-120 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.2 |
18 Sep 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-18 19:15
Updated : 2024-09-25 17:08
NVD link : CVE-2024-34057
Mitre link : CVE-2024-34057
CVE.ORG link : CVE-2024-34057
JSON object : View
Products Affected
siemens
- sicam_s8000
- sicam_a8000_firmware
- sicam_a8000
- sicam_egs_firmware
- sicam_scc
- sitipe_at
- sicam_egs
- sicam_scc_firmware
trianglemicroworks
- iec_61850_source_code_library
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')