Review reviewHigh
CVE-2024-36702
libiec61850
libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c.
- CVSS
- 7.4
- EPSS
- 0.24% 15.7% percentile
- CISA KEV
- Not listed
- Published
- 2024.06.12
libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c.
The CVSS severity warrants an early asset and exposure review.
libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c.
Confirm exposure before applying a vendor-supported change.
Confirm that libiec61850 and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.