Description
OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame processing. A specially crafted SV frame can cause the affected process to terminate, disrupting alert processing for Sampled Values traffic. The vulnerability does not affect overall system availability or the processing of other traffic types, and the process is automatically restarted, and the failure is immediately reported to the user.
Published: 2026-08-06
Score: 1.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE-2026-16316 reveals an improper input validation in OMICRON StationGuard 4.00’s handling of IEC 61850 Sampled Values (SV) frames, allowing a specially crafted frame to crash the SV processing process. The crash causes a brief loss of alert handling for SV traffic while the process is automatically restarted and the failure is reported to the user. Consequently, the vulnerability provides a limited denial‑of‑service effect that affects only the SV service and does not compromise overall system availability.

Affected Systems

OMICRON electronics GmbH’s StationGuard 4.00 is impacted. The vulnerability exists in this version of the product and no other products or versions are indicated.

Risk and Exploitability

With an extremely low CVSS score of 1.3 and no EPSS data, the likelihood of exploitation is low. The vulnerability does not appear on the KEV list. An attacker would need to be able to inject a malicious SV frame onto the IEC 61850 network segment containing the StationGuard instance and would need to send a specially crafted frame. Because the process automatically restarts and the failure is reported, the impact would be brief and limited to disruption of sampled‑value alerts only.

Generated by OpenCVE AI on August 6, 2026 at 17:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update OMICRON StationGuard to the latest available firmware that includes the input validation fix.
  • If a patch is not yet released, isolate the StationGuard instance or block the IEC 61850 network segment from untrusted SV producers to prevent malicious frames from reaching the service.
  • Continuously monitor StationGuard logs for SV process restarts and configure alerts for repeated failures to detect potential abuse.

Generated by OpenCVE AI on August 6, 2026 at 17:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame processing. A specially crafted SV frame can cause the affected process to terminate, disrupting alert processing for Sampled Values traffic. The vulnerability does not affect overall system availability or the processing of other traffic types, and the process is automatically restarted, and the failure is immediately reported to the user.
Title Malformed IEC 61850 Sampled Values frames cause partial denial of service in StationGuard
First Time appeared Omicron Electronics Gmbh
Omicron Electronics Gmbh omicron Stationguard
Weaknesses CWE-20
CPEs cpe:2.3:a:omicron_electronics_gmbh:omicron_stationguard:4.00:*:*:*:*:*:*:*
Vendors & Products Omicron Electronics Gmbh
Omicron Electronics Gmbh omicron Stationguard
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 1.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/R:A/RE:M'}


Subscriptions

Omicron Electronics Gmbh Omicron Stationguard
cve-icon MITRE

Status: PUBLISHED

Assigner: OMICRON

Published:

Updated: 2026-08-06T14:44:12.907Z

Reserved: 2026-07-20T15:52:14.993Z

Link: CVE-2026-16316

cve-icon Vulnrichment

Updated: 2026-08-06T14:44:09.785Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T17:15:01Z

Weaknesses
  • CWE-20

    Improper Input Validation