mz-automation CVE Vulnerabilities & Metrics

Focus on mz-automation vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About mz-automation Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with mz-automation. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total mz-automation CVEs: 33
Earliest CVE date: 30 Oct 2018, 06:29 UTC
Latest CVE date: 13 Apr 2023, 18:15 UTC

Latest CVE reference: CVE-2023-27772

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical mz-automation CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.22

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 7
4.0-6.9 22
7.0-8.9 4
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS mz-automation CVEs

These are the five CVEs with the highest CVSS scores for mz-automation, sorted by severity first and recency.

All CVEs for mz-automation

CVE-2023-27772 mz-automation vulnerability CVSS: 0 13 Apr 2023, 18:15 UTC

libiec61850 v1.5.1 was discovered to contain a segmentation violation via the function ControlObjectClient_setOrigin() at /client/client_control.c.

CVE-2023-23205 mz-automation vulnerability CVSS: 0 24 Feb 2023, 16:15 UTC

An issue was discovered in lib60870 v2.3.2. There is a memory leak in lib60870/lib60870-C/examples/multi_client_server/multi_client_server.c.

CVE-2022-3976 mz-automation vulnerability CVSS: 0 13 Nov 2022, 14:15 UTC

A vulnerability has been found in MZ Automation libiec61850 up to 1.4 and classified as critical. This vulnerability affects unknown code of the file src/mms/iso_mms/client/mms_client_files.c of the component MMS File Services. The manipulation of the argument filename leads to path traversal. Upgrading to version 1.5 is able to address this issue. The name of the patch is 10622ba36bb3910c151348f1569f039ecdd8786f. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-213556.

CVE-2022-2973 mz-automation vulnerability CVSS: 0 23 Sep 2022, 16:15 UTC

MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) uses a NULL pointer in certain situations. which could allow an attacker to crash the server.

CVE-2022-2972 mz-automation vulnerability CVSS: 0 23 Sep 2022, 16:15 UTC

MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) is vulnerable to a stack-based buffer overflow, which could allow an attacker to crash the device or remotely execute arbitrary code.

CVE-2022-2971 mz-automation vulnerability CVSS: 0 23 Sep 2022, 16:15 UTC

MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) accesses a resource using an incompatible type, which could allow an attacker to crash the server with a malicious payload.

CVE-2022-2970 mz-automation vulnerability CVSS: 0 23 Sep 2022, 16:15 UTC

MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) does not sanitize input before memcpy is used, which could allow an attacker to crash the device or remotely execute arbitrary code.

CVE-2022-21159 mz-automation vulnerability CVSS: 5.0 15 Apr 2022, 16:15 UTC

A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec61850 1.5.0. A specially-crafted series of network requests can lead to denial of service. An attacker can send a sequence of malformed iec61850 messages to trigger this vulnerability.

CVE-2022-1302 mz-automation vulnerability CVSS: 5.0 12 Apr 2022, 08:15 UTC

In the MZ Automation LibIEC61850 in versions prior to 1.5.1 an unauthenticated attacker can craft a goose message, which may result in a denial of service.

CVE-2021-45773 mz-automation vulnerability CVSS: 5.0 14 Jan 2022, 20:15 UTC

A NULL pointer dereference in CS104_IPAddress_setFromString at src/iec60870/cs104/cs104_slave.c of lib60870 commit 0d5e76e can lead to a segmentation fault or application crash.

CVE-2021-45769 mz-automation vulnerability CVSS: 5.0 14 Jan 2022, 20:15 UTC

A NULL pointer dereference in AcseConnection_parseMessage at src/mms/iso_acse/acse.c of libiec61850 v1.5.0 can lead to a segmentation fault or application crash.

CVE-2021-21778 mz-automation vulnerability CVSS: 5.0 25 Aug 2021, 19:15 UTC

A denial of service vulnerability exists in the ASDU message processing functionality of MZ Automation GmbH lib60870.NET 2.2.0. A specially crafted network request can lead to loss of communications. An attacker can send an unauthenticated message to trigger this vulnerability.

CVE-2020-15158 mz-automation vulnerability CVSS: 7.5 26 Aug 2020, 18:15 UTC

In libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer underflow will happen leading to heap buffer overflow. This can cause an application crash or on some platforms even the execution of remote code. If your application is used in open networks or there are untrusted nodes in the network it is highly recommend to apply the patch. This was patched with commit 033ab5b. Users of version 1.4.x should upgrade to version 1.4.3 when available. As a workaround changes of commit 033ab5b can be applied to older versions.

CVE-2020-7054 mz-automation vulnerability CVSS: 6.8 14 Jan 2020, 21:15 UTC

MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c in libIEC61850 through 1.4.0 has a heap-based buffer overflow when parsing the MMS_BIT_STRING data type.

CVE-2019-19958 mz-automation vulnerability CVSS: 4.3 24 Dec 2019, 22:15 UTC

In libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue that could lead to an attempted excessive memory allocation and denial of service.

CVE-2019-19957 mz-automation vulnerability CVSS: 4.3 24 Dec 2019, 22:15 UTC

In libIEC61850 1.4.0, getNumberOfElements in mms/iso_mms/server/mms_access_result.c has an out-of-bounds read vulnerability, related to bufPos and elementLength.

CVE-2019-19944 mz-automation vulnerability CVSS: 4.3 23 Dec 2019, 19:15 UTC

In libIEC61850 1.4.0, BerDecoder_decodeUint32 in mms/asn1/ber_decode.c has an out-of-bounds read, related to intLen and bufPos.

CVE-2019-19931 mz-automation vulnerability CVSS: 6.8 23 Dec 2019, 03:15 UTC

In libIEC61850 1.4.0, MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c has a heap-based buffer overflow.

CVE-2019-19930 mz-automation vulnerability CVSS: 4.3 23 Dec 2019, 03:15 UTC

In libIEC61850 1.4.0, MmsValue_newOctetString in mms/iso_mms/common/mms_value.c has an integer signedness error that can lead to an attempted excessive memory allocation.

CVE-2019-16510 mz-automation vulnerability CVSS: 5.0 19 Sep 2019, 16:15 UTC

libIEC61850 through 1.3.3 has a use-after-free in MmsServer_waitReady in mms/iso_mms/server/mms_server.c, as demonstrated by server_example_goose.

CVE-2019-1010300 mz-automation vulnerability CVSS: 5.0 15 Jul 2019, 18:15 UTC

mz-automation libiec61850 1.3.2 1.3.1 1.3.0 is affected by: Buffer Overflow. The impact is: Software crash. The component is: server_example_complex_array. The attack vector is: Send a specific MMS protocol packet.

CVE-2019-6719 mz-automation vulnerability CVSS: 5.0 23 Jan 2019, 22:29 UTC

An issue has been found in libIEC61850 v1.3.1. There is a use-after-free in the getState function in mms/iso_server/iso_server.c, as demonstrated by examples/server_example_goose/server_example_goose.c and examples/server_example_61400_25/server_example_61400_25.c.

CVE-2019-6138 mz-automation vulnerability CVSS: 5.0 11 Jan 2019, 17:29 UTC

An issue has been found in libIEC61850 v1.3.1. Memory_malloc and Memory_calloc in hal/memory/lib_memory.c have memory leaks when called from mms/iso_mms/common/mms_value.c, server/mms_mapping/mms_mapping.c, and server/mms_mapping/mms_sv.c (via common/string_utilities.c), as demonstrated by iec61850_9_2_LE_example.c.

CVE-2019-6137 mz-automation vulnerability CVSS: 5.0 11 Jan 2019, 17:29 UTC

An issue was discovered in lib60870 2.1.1. LinkLayer_setAddress in link_layer/link_layer.c has a NULL pointer dereference.

CVE-2019-6136 mz-automation vulnerability CVSS: 5.0 11 Jan 2019, 17:29 UTC

An issue has been found in libIEC61850 v1.3.1. Ethernet_setProtocolFilter in hal/ethernet/linux/ethernet_linux.c has a SEGV, as demonstrated by sv_subscriber_example.c and sv_subscriber.c.

CVE-2019-6135 mz-automation vulnerability CVSS: 5.0 11 Jan 2019, 17:29 UTC

An issue has been found in libIEC61850 v1.3.1. Memory_malloc in hal/memory/lib_memory.c has a memory leak when called from Asn1PrimitiveValue_create in mms/asn1/asn1_ber_primitive_value.c, as demonstrated by goose_publisher_example.c and iec61850_9_2_LE_example.c.

CVE-2018-19185 mz-automation vulnerability CVSS: 7.5 12 Nov 2018, 05:29 UTC

An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c. This is exploitable even after CVE-2018-18834 has been patched, with a different dataSetValue sequence than the CVE-2018-18834 attack vector.

CVE-2018-19122 mz-automation vulnerability CVSS: 4.3 09 Nov 2018, 11:29 UTC

An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in Ethernet_sendPacket in ethernet_bsd.c.

CVE-2018-19121 mz-automation vulnerability CVSS: 4.3 09 Nov 2018, 11:29 UTC

An issue has been found in libIEC61850 v1.3. It is a SEGV in Ethernet_receivePacket in ethernet_bsd.c.

CVE-2018-19093 mz-automation vulnerability CVSS: 5.0 07 Nov 2018, 19:29 UTC

An issue has been found in libIEC61850 v1.3. It is a SEGV in ControlObjectClient_setCommandTerminationHandler in client/client_control.c. NOTE: the software maintainer disputes this because it requires incorrect usage of the client_example_control program

CVE-2018-18957 mz-automation vulnerability CVSS: 7.5 05 Nov 2018, 22:29 UTC

An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c.

CVE-2018-18937 mz-automation vulnerability CVSS: 5.0 05 Nov 2018, 09:29 UTC

An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in ClientDataSet_getValues in client/ied_connection.c.

CVE-2018-18834 mz-automation vulnerability CVSS: 7.5 30 Oct 2018, 06:29 UTC

An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c.