Description
The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS
connection establishment. When parsing certain fields within the
calling AP title, an attacker controlled length value of zero or one may
cause the parser to read past the end of a heap buffer.
Published: 2026-07-30
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an out-of-bounds read in the ACSE layer of the libiec61850 library, triggered when parsing AARQ PDUs during MMS connection establishment. An attacker who can influence the length field to zero or one causes the parser to read past the end of a heap buffer, potentially leaking sensitive memory contents and compromising confidentiality. The weakness is identified as CWE‑125.

Affected Systems

MZ Automation GmbH’s libiec61850 library is affected. Versions prior to 1.6.2 are vulnerable; the vendor recommends updating to 1.6.2 to receive a fix.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. EPSS score of < 1% indicates a very low exploitation probability and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. However, because the issue is triggered via network traffic in MMS sessions, a remote attacker with network access to an IEC 61850 implementation could craft a malicious AARQ PDU to obtain memory data. The risk is moderate, especially in environments where the library is exposed to untrusted network traffic.

Generated by OpenCVE AI on August 3, 2026 at 10:22 UTC.

Remediation

Vendor Solution

MZ Automation GmbH recommends that users update to version 1.6.2.


OpenCVE Recommended Actions

  • Update libiec61850 to version 1.6.2 or later as recommended by MZ Automation.
  • Limit MMS connection initiation to trusted control servers by configuring firewall rules or network segmentation, thereby reducing the attack surface if an upgrade is delayed.
  • Enhance runtime protection by enabling stack canaries, address space layout randomization, or other memory‑safety mechanisms to mitigate the impact of similar out‑of‑bounds reads in case the vulnerability remains unpatched.

Generated by OpenCVE AI on August 3, 2026 at 10:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mz-automation
Mz-automation libiec61850
Vendors & Products Mz-automation
Mz-automation libiec61850

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer.
Title MZ Automation libiec61850 Out-of-bounds Read
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mz-automation Libiec61850
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-31T15:52:20.133Z

Reserved: 2026-07-27T19:32:49.404Z

Link: CVE-2026-56758

cve-icon Vulnrichment

Updated: 2026-07-31T15:52:14.033Z

cve-icon NVD

Status : Received

Published: 2026-07-30T23:16:51.517

Modified: 2026-07-31T16:17:07.867

Link: CVE-2026-56758

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:45:03Z

Weaknesses