Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. The resulting buffer overflow can cause a crash, resulting in a denial of service.
References
Link | Resource |
---|---|
https://trianglemicroworks.com/products/source-code-libraries/iec-61850-scl-pages/what%27s-new | Release Notes |
https://www.cisa.gov/news-events/ics-advisories/icsa-24-256-16 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
|
History
25 Sep 2024, 17:08
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:siemens:sicam_a8000_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:siemens:sicam_scc:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:sicam_scc_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:sicam_egs_firmware:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:sicam_s8000:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:sitipe_at:*:*:*:*:*:*:*:* cpe:2.3:h:siemens:sicam_egs:-:*:*:*:*:*:*:* cpe:2.3:a:trianglemicroworks:iec_61850_source_code_library:*:*:*:*:*:*:*:* cpe:2.3:h:siemens:sicam_a8000:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
First Time |
Siemens sicam S8000
Siemens sicam A8000 Siemens sicam Scc Siemens sitipe At Siemens sicam Egs Firmware Siemens Trianglemicroworks iec 61850 Source Code Library Trianglemicroworks Siemens sicam Egs Siemens sicam A8000 Firmware Siemens sicam Scc Firmware |
|
References | () https://trianglemicroworks.com/products/source-code-libraries/iec-61850-scl-pages/what%27s-new - Release Notes | |
References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-256-16 - Third Party Advisory, US Government Resource |
19 Sep 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE | CWE-120 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.2 |
18 Sep 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-18 19:15
Updated : 2024-09-25 17:08
NVD link : CVE-2024-34057
Mitre link : CVE-2024-34057
CVE.ORG link : CVE-2024-34057
JSON object : View
Products Affected
siemens
- sicam_egs
- sitipe_at
- sicam_s8000
- sicam_a8000_firmware
- sicam_scc
- sicam_scc_firmware
- sicam_a8000
- sicam_egs_firmware
trianglemicroworks
- iec_61850_source_code_library
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')