CVSS
9.8
CVSS v3.1
EPSS
0.4%
Exploit Prediction Score
Published
August 6, 2026
Exploitability
EPSS probability 0.4%
A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the current ASDU frame before encoding object fields and segment data
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).