Description
The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service.
Published: 2026-07-23
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out-of-bounds read (CWE‑125) that can be triggered when the lib60870 parsing routine processes malformed input. This flaw may cause the parsing process to crash, resulting in a denial of service. No other impact such as code execution or credential compromise is described in the official data.

Affected Systems

The affected product is MZ Automation lib60870. Versions older than 2.4.1 are known to contain the issue. No specific operating system or deployment context is mentioned in the CVE data.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be network-based, as the flaw occurs during parsing of input data; an attacker would need to supply crafted input to the component that uses the vulnerable library to trigger a crash and deny availability.

Generated by OpenCVE AI on August 3, 2026 at 20:56 UTC.

Remediation

Vendor Solution

MZ automation recommends users update to version 2.4.1 or later. Documentation can be found at https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv. https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv


OpenCVE Recommended Actions

  • Update lib60870 to version 2.4.1 or later as recommended by MZ Automation.
  • If an immediate update is not feasible, restrict or block input that could reach the parsing function, such as by applying firewall rules or isolating the service that uses the vulnerable library.
  • Monitor the service for crashes or unavailability, and consider redeploying a hardened configuration once the update is applied.

Generated by OpenCVE AI on August 3, 2026 at 20:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Mz-automation
Mz-automation lib60870
Vendors & Products Mz-automation
Mz-automation lib60870

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service.
Title Out-of-bounds Read in MZ Automation lib60870
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mz-automation Lib60870
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-24T13:36:36.942Z

Reserved: 2026-07-17T00:29:22.437Z

Link: CVE-2026-16002

cve-icon Vulnrichment

Updated: 2026-07-24T13:36:33.565Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T21:17:03.363

Modified: 2026-07-30T14:12:18.697

Link: CVE-2026-16002

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:00:12Z

Weaknesses