Description
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an
inflated object count causes TestCommand_getFromBuffer to read one byte
past the end of the heap-allocated message buffer.
Published: 2026-07-30
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A crafted IEC 60870‑5‑104 I‑frame with TypeID 104 inflates the object count, causing TestCommand_getFromBuffer to read one byte past the end of the heap‑allocated message buffer. This out‑of‑bounds read may leak adjacent memory contents to an attacker, providing confidential information that could be used to further compromise the system. The weakness is classified as CWE‑125, a buffer read beyond the allocated memory, and the CVSS score of 6.9 reflects a moderate severity with a medium impact potential on confidentiality.

Affected Systems

The vulnerability exists in the MZ Automation lib60870 library. All installations running versions prior to the release of 2.4.1 are affected, as the advisory specifically targets versions before that update. No other vendors or products are listed as impacted in the CNA data.

Risk and Exploitability

The EPSS score of 0.00264 reveals a very low probability of exploitation, but the CVSS rating indicates remote exploitation is possible. Based on the description, the most likely attack vector involves an attacker sending a malicious IEC 60870‑5‑104 I‑frame over the network to a device or service that uses lib60870. Since the flaw is a simple out‑of‑bounds read on the parser, no additional authentication or privileges are required beyond network access to the relevant port. The vulnerability is not yet listed in the CISA KEV catalog. Given the CVSS score of 6.9 and the lack of public exploits, the risk is considered moderate but should be addressed promptly to reduce the attack surface.

Generated by OpenCVE AI on August 3, 2026 at 10:20 UTC.

Remediation

Vendor Solution

MZ Automation recommends users update to version 2.4.1 when available. See MZ Automation advisory for more information:   https://github.com/mz-automation/lib60870/security/advisories/GHSA-g3w7-x5rx-83xm


OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch to lib60870 version 2.4.1 or newer.
  • Use firewall or network segmentation to restrict IEC 60870‑5‑104 traffic to trusted upstream devices.
  • Monitor logs for abnormal IEC 60870‑5‑104 I‑frame patterns and block traffic that does not conform to expected object counts.

Generated by OpenCVE AI on August 3, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Mz-automation
Mz-automation lib60870
Vendors & Products Mz-automation
Mz-automation lib60870

Thu, 30 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Description A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.
Title MZ Automation lib60870 Out-of-bounds Read
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Mz-automation Lib60870
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-31T16:00:07.592Z

Reserved: 2026-07-16T22:10:53.022Z

Link: CVE-2026-61893

cve-icon Vulnrichment

Updated: 2026-07-31T15:59:58.397Z

cve-icon NVD

Status : Received

Published: 2026-07-30T23:16:51.760

Modified: 2026-07-31T16:17:08.637

Link: CVE-2026-61893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:30:18Z

Weaknesses