CVE-2022-2970
Last modified
CVE-2022-2970 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) does not sanitize input before memcpy is used, which could allow an attacker to crash the device or remotely execute arbitrary code.. EPSS estimates a 1.06% chance of exploitation in the next 30 days.
Description
MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) does not sanitize input before memcpy is used, which could allow an attacker to crash the device or remotely execute arbitrary code.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mz-Automation | Libiec61850 | < 1.5.0 |
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-251-01Third Party Advisory, US Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-251-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2970?
How severe is CVE-2022-2970?
How do I fix CVE-2022-2970?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-29689CSCMS Music Portal System v4.2 was discovered to contain a b…7.2
- CVE-2022-2969Delta Industrial Automation DIALink versions prior to v1.5.0…7.5
- CVE-2022-29692Unicorn Engine v1.0.3 was discovered to contain a use-after-…7.8
- CVE-2022-29693Unicorn Engine v2.0.0-rc7 and below was discovered to contai…7.5
- CVE-2022-29694Unicorn Engine v2.0.0-rc7 and below was discovered to contai…7.5
- CVE-2022-29695Unicorn Engine v2.0.0-rc7 contains memory leaks caused by an…7.5
- CVE-2022-29700A lack of password length restriction in Zammad v5.1.0 allow…7.5
- CVE-2022-29701A lack of rate limiting in the 'forgot password' feature of …7.5
- CVE-2022-29704BrowsBox CMS v4.0 was discovered to contain a SQL injection …9.8
- CVE-2022-29709CommuniLink Internet Limited CLink Office v2.0 was discovere…7.5
- CVE-2022-2971MZ Automation's libIEC61850 (versions 1.4 and prior; version…7.5
- CVE-2022-29710A cross-site scripting (XSS) vulnerability in uploadConfirm.…6.1
Are you affected by CVE-2022-2970?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
