CyberRota Analysis
AI-GeneratedThe vulnerability affects the GOOSE subscriber component, which fails to properly validate the UTC timestamp field in unauthenticated IEC 61850 GOOSE Layer-2 multicast messages. An attacker can exploit this flaw by sending a specially crafted GOOSE frame with an undersized timestamp, leading to a heap out-of-bounds read that crashes the process and causes a denial-of-service condition. Organizations utilizing IEC 61850 protocols in their network infrastructure should prioritize addressing this issue to maintain service availability and security.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition.