MZ Automation GmbH libiec61850
Multiple vulnerabilities in MZ Automation GmbH libiec61850 allow for denial-of-service attacks.
Summary
Multiple vulnerabilities have been discovered in MZ Automation GmbH's libiec61850 software, affecting versions prior to 1.6.2. These vulnerabilities, primarily heap out-of-bounds reads, can be exploited by attackers to cause a denial-of-service condition on affected devices. The affected software is used in critical infrastructure sectors, particularly energy, and is deployed worldwide.
Full text
ICS Advisory MZ Automation GmbH libiec61850 Release DateJuly 30, 2026 Alert CodeICSA-26-211-10 Related topics: Industrial Control System Vulnerabilities , Industrial Control Systems View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device. The following versions of MZ Automation GmbH libiec61850 are affected: libiec61850 <1.6.2 (CVE-2026-66720, CVE-2026-66369, CVE-2026-63550, CVE-2026-65421, CVE-2026-66364, CVE-2026-66349, CVE-2026-56758, CVE-2026-66360) CVSS Vendor Equipment Vulnerabilities v3 7.5 MZ Automation GmbH MZ Automation GmbH libiec61850 Out-of-bounds Read Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-66720 The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor:MZ Automation GmbH Product Version:MZ Automation GmbH libiec61850: <1.6.2 Product Status:known_affected Remediations MitigationMZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-66369 The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor:MZ Automation GmbH Product Version:MZ Automation GmbH libiec61850: <1.6.2 Product Status:known_affected Remediations MitigationMZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-63550 The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position incorrectly, leading to a heap out-of-bounds read. This condition causes the MMS handling process to terminate unexpectedly, resulting in a denial-of-service. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor:MZ Automation GmbH Product Version:MZ Automation GmbH libiec61850: <1.6.2 Product Status:known_affected Remediations MitigationMZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-65421 The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor:MZ Automation GmbH Product Version:MZ Automation GmbH libiec61850: <1.6.2 Product Status:known_affected Remediations MitigationMZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-66364 The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length, causing the parser to over read by one byte. This out-of-bounds read reliably terminates the subscriber process, resulting in a denial-of-service condition. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor:MZ Automation GmbH Product Version:MZ Automation GmbH libiec61850: <1.6.2 Product Status:known_affected Remediations MitigationMZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-66349 The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing bounds check. This results in a one byte heap out-of-bounds read and causes the MMS service process to terminate, leading to a denial-of-service condition. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor:MZ Automation GmbH Product Version:MZ Automation GmbH libiec61850: <1.6.2 Product Status:known_affected Remediations MitigationMZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 6.9 MEDIUM CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-56758 The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor:MZ Automation GmbH Product Version:MZ Automation GmbH libiec61850: <1.6.2 Product Status:known_affected Remediations MitigationMZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 6.9 MEDIUM CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-66360 The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap over read. This condition occurs before MMS session establishment, a crafted TCP/102 connection attempt can trigger the issue. The resulting over read causes the process to terminate, leading to a denial of service condition. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor:MZ Automation GmbH Product Version:MZ Automation GmbH libiec61850: <1.6.2 Product Status:known_affected Remediations MitigationMZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/
Indicators of Compromise
- cve — CVE-2026-66720
- cve — CVE-2026-66369
- cve — CVE-2026-65421
- cve — CVE-2026-66364
- cve — CVE-2026-66349
- cve — CVE-2026-56758
- cve — CVE-2026-66360