Description
The ISO Presentation layer contains a flaw in the handling of specific
parameters during normal mode negotiation. A missing length check in the
processing of the encoded presentation data allows an attacker
controlled field with a zero length value to trigger a bounded heap over
read. This condition occurs before MMS session establishment, a crafted
TCP/102 connection attempt can trigger the issue. The resulting over
read causes the process to terminate, leading to a denial of service
condition.
Published: 2026-07-30
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The issue resides in the ISO Presentation layer of MZ Automation GmbH’s libiec61850 library. During normal mode negotiation, a missing length check while decoding presented data allows an attacker to supply a field with a zero length, which triggers a bounded heap overread before the MMS session is established. The overread causes the process to terminate, resulting in a denial of service for the affected system.

Affected Systems

The vulnerability affects the libiec61850 library distributed by MZ Automation GmbH. No specific version range is listed, but the vendor recommends updating to version 1.6.2 to resolve the flaw.

Risk and Exploitability

The CVSS score is 8.7, indicating a high severity vulnerability. EPSS score is < 1%, and the flaw is not listed in the CISA catalog. Attacks occur remotely via a crafted TCP connection to port 102 before the MMS session begins. Exploitation requires network reachability to the target device and does not provide information disclosure or privilege escalation; the impact is limited to causing the associated process to crash and deny service.

Generated by OpenCVE AI on August 3, 2026 at 10:22 UTC.

Remediation

Vendor Solution

MZ Automation GmbH recommends that users update to version 1.6.2.


OpenCVE Recommended Actions

  • Update the libiec61850 library to version 1.6.2 as recommended by MZ Automation.
  • If an upgrade cannot be applied immediately, block inbound TCP traffic on port 102 or isolate devices using the library from untrusted networks to prevent remote session initiation.
  • Apply or develop a patched version of the library that includes bounds checks for encoded presentation data to prevent out‑of‑bounds reads.
  • Set up monitoring of application logs for abnormal termination events that may indicate exploitation attempts.

Generated by OpenCVE AI on August 3, 2026 at 10:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Mz-automation
Mz-automation libiec61850
Vendors & Products Mz-automation
Mz-automation libiec61850

Thu, 30 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap over read. This condition occurs before MMS session establishment, a crafted TCP/102 connection attempt can trigger the issue. The resulting over read causes the process to terminate, leading to a denial of service condition.
Title MZ Automation libiec61850 Out-of-bounds Read
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mz-automation Libiec61850
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-31T15:50:41.354Z

Reserved: 2026-07-27T19:32:49.407Z

Link: CVE-2026-66360

cve-icon Vulnrichment

Updated: 2026-07-31T15:50:33.546Z

cve-icon NVD

Status : Received

Published: 2026-07-30T23:16:53.070

Modified: 2026-07-31T16:17:10.493

Link: CVE-2026-66360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:30:18Z

Weaknesses