Description
The GOOSE parser contains an off-by-one boundary-handling flaw that can
be triggered by a single unauthenticated Layer-2 multicast frame on the
process bus. When specific GOOSE message fields are processed, the
parser advances its internal buffer position incorrectly, resulting in a
heap out-of-bounds read. On affected platforms, this condition reliably
terminates the subscriber process and causes a denial-of-service.
Published: 2026-07-30
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An off‑by‑one error in the GOOSE parser of libiec61850 causes a heap out‑of‑bounds read when certain message fields are processed. The read does not corrupt memory but forces the subscriber process to terminate, resulting in a denial‑of‑service condition on the affected platform.

Affected Systems

The flaw affects MZ Automation GmbH’s libiec61850 library. All releases prior to the vendor’s 1.6.2 update are impacted. Systems that depend on libiec61850 to decode IEC 61850 GOOSE frames must upgrade to avoid interruption.

Risk and Exploitability

The CVSS score of 7.1 reflects moderate‑to‑high severity, while the EPSS score of < 1 % indicates the vulnerability is rarely exploited in the wild and the lack of a KEV listing reinforces that it has not yet been widely used. An attacker must be able to inject a single un‑authenticated Layer‑2 multicast frame onto the plant process bus to trigger the flaw, which requires local or network proximity to the process bus.

Generated by OpenCVE AI on August 2, 2026 at 04:51 UTC.

Remediation

Vendor Solution

MZ Automation GmbH recommends that users update to version 1.6.2.


OpenCVE Recommended Actions

  • Upgrade libiec61850 to version 1.6.2 as recommended by MZ Automation.
  • Restart any services or processes that use the library after applying the update so that the new code takes effect.
  • Block or filter untrusted Layer‑2 GOOSE multicast traffic or isolate the process bus through VLAN or segmentation to reduce the likelihood of an attacker reaching the vulnerable parser.

Generated by OpenCVE AI on August 2, 2026 at 04:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Mz-automation
Mz-automation libiec61850
Vendors & Products Mz-automation
Mz-automation libiec61850

Thu, 30 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Description The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service.
Title MZ Automation libiec61850 Out-of-bounds Read
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mz-automation Libiec61850
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-31T19:22:19.970Z

Reserved: 2026-07-27T19:32:49.390Z

Link: CVE-2026-66369

cve-icon Vulnrichment

Updated: 2026-07-31T19:22:15.759Z

cve-icon NVD

Status : Received

Published: 2026-07-30T23:16:53.377

Modified: 2026-07-31T20:16:54.120

Link: CVE-2026-66369

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:00:05Z

Weaknesses