Description
The MMS BER decoder contains a flaw in decoding fixed-width BER fields
(boolean/integer): an attacker-supplied length value is not validated,
causing a read past the end of a heap buffer. This leads to termination
of the MMS service process and a denial-of-service condition.
Published: 2026-07-30
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer over-read occurs in the MMS BER decoder when handling fixed-width boolean or integer fields. The decoder fails to validate an attacker‐supplied length value, resulting in a read past the end of a heap buffer. This flaw causes the MMS service process to terminate, producing a server‑side denial‑of‑service condition. The weakness is a classic out‑of‑bounds read, identified as CWE‑125.

Affected Systems

Vendor: MZ Automation GmbH; Product: libiec61850. All releases prior to 1.6.2 are affected; the vendor’s advisory recommends updating to version 1.6.2 to remove the flaw.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, indicating high severity. EPSS indicates a probability of exploitation below 1%, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is remote network traffic to the MMS service, where an attacker can craft a malformed MMS packet that triggers the over‑read and crashes the process, causing a denial of service.

Generated by OpenCVE AI on August 2, 2026 at 04:51 UTC.

Remediation

Vendor Solution

MZ Automation GmbH recommends that users update to version 1.6.2.


OpenCVE Recommended Actions

  • Update the libiec61850 library to 1.6.2 or later, following the vendor’s recommendation.
  • Restart the MMS service after applying the update to clear any crashed processes.
  • If an upgrade cannot be performed immediately, restrict network access to the MMS interfaces to trusted sources only, thereby limiting the ability of an attacker to inject malformed packets.

Generated by OpenCVE AI on August 2, 2026 at 04:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Mz-automation
Mz-automation libiec61850
Vendors & Products Mz-automation
Mz-automation libiec61850

Thu, 30 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition.
Title MZ Automation libiec61850 Out-of-bounds Read
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mz-automation Libiec61850
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-31T15:55:36.578Z

Reserved: 2026-07-27T19:32:49.396Z

Link: CVE-2026-65421

cve-icon Vulnrichment

Updated: 2026-07-31T15:55:31.946Z

cve-icon NVD

Status : Received

Published: 2026-07-30T23:16:52.597

Modified: 2026-07-31T16:17:09.443

Link: CVE-2026-65421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:00:05Z

Weaknesses