Description
The MMS BER decoder contains a boundary-handling flaw in the processing
of certain fields within confirmed-request messages. When a crafted
BER-encoded element is received over an established MMS session (TCP
port 102), the decoder may advance its internal read position
incorrectly, leading to a heap out-of-bounds read. This condition causes
the MMS handling process to terminate unexpectedly, resulting in a
denial-of-service.
Published: 2026-07-30
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The libiec61850 MMS BER decoder contains a boundary‑handling flaw in the processing of confirmed‑request messages. When a crafted BER‑encoded element is received over an established MMS session on TCP port 102, the decoder may advance its internal read pointer incorrectly, causing a heap out‑of‑bounds read that terminates the MMS handling process and results in a denial of service.

Affected Systems

MZ Automation GmbH’s libiec61850 library is affected. The vulnerability exists in versions prior to 1.6.2, which users should update to the latest release that addresses the issue. Devices running libiec61850 that accept MMS traffic on TCP port 102 are particularly at risk.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high impact of the crash, while the EPSS score of 0.25% shows a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation data. The likely attack vector is remote, as an attacker must be able to send a crafted BER message to a device over the MMS session on port 102. No publicly known exploits have been disclosed, but the severity warrants proactive mitigation.

Generated by OpenCVE AI on August 3, 2026 at 10:21 UTC.

Remediation

Vendor Solution

MZ Automation GmbH recommends that users update to version 1.6.2.


OpenCVE Recommended Actions

  • Upgrade libiec61850 to version 1.6.2 or later.
  • If immediate patch is not possible, apply a network firewall rule to block inbound TCP connections on port 102 from untrusted sources to prevent the crafted message from reaching the vulnerable decoder.
  • Continuously monitor system logs for unexpected terminations of MMS handling processes and consider deploying intrusion detection to alert on anomalous traffic patterns targeting port 102.

Generated by OpenCVE AI on August 3, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Mz-automation
Mz-automation libiec61850
Vendors & Products Mz-automation
Mz-automation libiec61850

Thu, 30 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Description The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position incorrectly, leading to a heap out-of-bounds read. This condition causes the MMS handling process to terminate unexpectedly, resulting in a denial-of-service.
Title MZ Automation libiec61850 Out-of-bounds Read
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mz-automation Libiec61850
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-31T15:57:05.901Z

Reserved: 2026-07-27T19:32:49.393Z

Link: CVE-2026-63550

cve-icon Vulnrichment

Updated: 2026-07-31T15:56:58.192Z

cve-icon NVD

Status : Received

Published: 2026-07-30T23:16:52.443

Modified: 2026-07-31T16:17:09.170

Link: CVE-2026-63550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:30:18Z

Weaknesses