{"id":"CVE-2022-21159","details":"A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec61850 1.5.0. A specially-crafted series of network requests can lead to denial of service. An attacker can send a sequence of malformed iec61850 messages to trigger this vulnerability.","modified":"2026-08-12T12:59:16.164930Z","published":"2022-04-15T16:00:21.545Z","database_specific":{"cna_assigner":"talos","cwe_ids":["CWE-835"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21159.json"},"references":[{"type":"WEB","url":"https://talosintelligence.com/vulnerability_reports/TALOS-2022-1467"},{"type":"WEB","url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1467"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21159.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-21159"},{"type":"FIX","url":"https://github.com/mz-automation/libiec61850/commit/cfa94cbf10302bedc779703f874ee2e8387a0721"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mz-automation/libiec61850","events":[{"introduced":"fcefc746fea286aeaa40d2f62240216da81c85e5"},{"fixed":"cfa94cbf10302bedc779703f874ee2e8387a0721"}],"database_specific":{"cpe":"cpe:2.3:a:mz-automation:libiec61850:1.5.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.5.0"},{"last_affected":"1.5.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.5.0","v1.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-21159.json","vanir_signatures_modified":"2026-08-12T12:59:16Z","vanir_signatures":[{"target":{"file":"src/mms/iso_presentation/iso_presentation.c"},"deprecated":false,"digest":{"line_hashes":["25213957932334231058944007225823008941","67471863485973758694629299555634988998","141217303716298442094824262701757012882","23607064311548028137475690767052629718"],"threshold":0.9},"id":"CVE-2022-21159-6c22e527","signature_type":"Line","signature_version":"v1","source":"https://github.com/mz-automation/libiec61850/commit/cfa94cbf10302bedc779703f874ee2e8387a0721"},{"signature_version":"v1","source":"https://github.com/mz-automation/libiec61850/commit/cfa94cbf10302bedc779703f874ee2e8387a0721","target":{"file":"src/mms/iso_presentation/iso_presentation.c","function":"parseNormalModeParameters"},"deprecated":false,"digest":{"function_hash":"30939351653663780092954731091689706048","length":1951},"id":"CVE-2022-21159-f6e94241","signature_type":"Function"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}