cvedb.io
CVE-2026-67873
UNKNOWN · CVSS n/a
EPSS exploitation probability: 0%
Published 2026-08-06T00:16:54.380 · Last modified 2026-08-06T00:16:54.380

Summary

A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the current ASDU frame before encoding object fields and segment data

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.