Description
The GOOSE payload parser contains a boundary handling flaw that can be
triggered by a single unauthenticated Layer 2 multicast frame on the
process bus. When processing specific payload fields, an attacker
controlled inner element length may exceed its enclosing length, causing
the parser to over read by one byte. This out-of-bounds read reliably
terminates the subscriber process, resulting in a denial-of-service
condition.
Published: 2026-07-30
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The GOOSE payload parser in MZ Automation's libiec61850 contains a boundary handling flaw that allows a controlled inner element length to exceed its enclosing length, resulting in an out-of-bounds read of one byte. This flaw causes the subscriber process to terminate reliably, leading to a denial‑of‑service condition without granting the attacker any other privileges. The weakness is associated with CWE‑125, an out‑of‑bounds read.

Affected Systems

The vulnerability affects MZ Automation GmbH's libiec61850 library. Users should upgrade to version 1.6.2 or later to obtain the fix. No other vendors or product versions are listed as affected.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. EPSS score is < 1%, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is a single unauthenticated Layer 2 multicast frame sent on the process bus, which an attacker with access to the network segment hosting the control system can deliver. This makes the exploit realistic for attackers with network reach into the process bus or those who can intercept or inject packets locally. The impact is limited to denial of service of the subscriber process, but repeated crashes can disrupt critical industrial control operations.

Generated by OpenCVE AI on August 3, 2026 at 10:21 UTC.

Remediation

Vendor Solution

MZ Automation GmbH recommends that users update to version 1.6.2.


OpenCVE Recommended Actions

  • Update libiec61850 to version 1.6.2 or later to eliminate the boundary handling flaw.
  • Configure the application to automatically restart the subscriber process upon detection of a crash, ensuring continued operation without manual intervention.
  • Implement or enable network packet filtering or intrusion detection to detect and block abnormal GOOSE payloads or suspected multicast frames that could trigger the false length condition.

Generated by OpenCVE AI on August 3, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Mz-automation
Mz-automation libiec61850
Vendors & Products Mz-automation
Mz-automation libiec61850

Thu, 30 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length, causing the parser to over read by one byte. This out-of-bounds read reliably terminates the subscriber process, resulting in a denial-of-service condition.
Title MZ Automation libiec61850 Out-of-bounds Read
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mz-automation Libiec61850
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-31T15:55:15.546Z

Reserved: 2026-07-27T19:32:49.399Z

Link: CVE-2026-66364

cve-icon Vulnrichment

Updated: 2026-07-31T15:55:11.764Z

cve-icon NVD

Status : Received

Published: 2026-07-30T23:16:53.223

Modified: 2026-07-31T16:17:10.617

Link: CVE-2026-66364

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:30:18Z

Weaknesses