Description
A crafted IEC 60870-5-104 I-frame with a declared object count exceeding
what fits in the ASDU body causes InformationObject_ParseObjectAddress
to read one byte past the end of the heap-allocated message buffer.
Published: 2026-07-30
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in MZ Automation lib60870 allows an attacker to craft an IEC 60870‑5‑104 I‑frame with an object count that exceeds the actual ASDU body size, causing the library function InformationObject_ParseObjectAddress to read one byte past the allocated message buffer. This out‑of‑bounds read can reveal arbitrary memory contents, potentially exposing sensitive control data or internal state. The weakness is a typical CWE‑125 buffer overread.

Affected Systems

Any installation of MZ Automation lib60870 that has not yet been updated to version 2.4.1 or later is susceptible. The vendor’s advisory specifically targets earlier releases of the library that lack the bounds‑checking fix.

Risk and Exploitability

With a CVSS score of 6.9, the vulnerability is considered medium severity. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed. The likely attack vector is remote, as the flaw is triggered by a crafted frame over the network protocol, so any device exposing IEC 60870‑5‑104 to untrusted networks could be targeted.

Generated by OpenCVE AI on August 3, 2026 at 10:20 UTC.

Remediation

Vendor Solution

MZ Automation recommends users update to version 2.4.1 when available. See MZ Automation advisory for more information:  https://github.com/mz-automation/lib60870/security/advisories/GHSA-7v97-jmwv-w5j7


OpenCVE Recommended Actions

  • Upgrade lib60870 to version 2.4.1 or later following the vendor’s security advisory.
  • If an immediate upgrade is not possible, block or filter IEC 60870‑5‑104 traffic from external or untrusted networks to prevent delivery of malicious frames to the vulnerable library.
  • Restrict system access by applying network segmentation and ensuring that only trusted IP addresses are allowed to communicate via IEC 60870‑5‑104 with the affected devices.

Generated by OpenCVE AI on August 3, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Mz-automation
Mz-automation lib60870
Vendors & Products Mz-automation
Mz-automation lib60870

Thu, 30 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Description A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer.
Title MZ Automation lib60870 Out-of-bounds Read
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Mz-automation Lib60870
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-31T19:23:47.085Z

Reserved: 2026-07-16T22:10:53.026Z

Link: CVE-2026-63033

cve-icon Vulnrichment

Updated: 2026-07-31T19:23:40.894Z

cve-icon NVD

Status : Received

Published: 2026-07-30T23:16:51.917

Modified: 2026-07-31T20:16:53.713

Link: CVE-2026-63033

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:30:18Z

Weaknesses