CVE-2024-34057

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
18/09/2024
Last modified:
25/09/2024

Description

Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. The resulting buffer overflow can cause a crash, resulting in a denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trianglemicroworks:iec_61850_source_code_library:*:*:*:*:*:*:*:* 12.2.0 (excluding)
cpe:2.3:o:siemens:sicam_a8000_firmware:*:*:*:*:*:*:*:* 05.30 (excluding)
cpe:2.3:h:siemens:sicam_a8000:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:sicam_scc_firmware:*:*:*:*:*:*:*:* 10.0 (excluding)
cpe:2.3:h:siemens:sicam_scc:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:sicam_egs_firmware:*:*:*:*:*:*:*:* 05.30 (excluding)
cpe:2.3:h:siemens:sicam_egs:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sicam_s8000:*:*:*:*:*:*:*:* 05.30 (excluding)
cpe:2.3:a:siemens:sitipe_at:*:*:*:*:*:*:*:*