CyberRota Analysis
AI-GeneratedThe vulnerability exists in the GOOSE parser, which is susceptible to an off-by-one boundary-handling flaw triggered by unauthenticated Layer-2 multicast frames. This flaw leads to a heap out-of-bounds read, resulting in the termination of the subscriber process and causing a denial-of-service condition. Organizations utilizing affected platforms should prioritize patching this vulnerability to mitigate potential service disruptions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service.