Description
The GOOSE subscriber component improperly validates the UTC timestamp
field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2
multicast messages. A specially crafted GOOSE frame containing an
undersized timestamp field can trigger a heap out-of-bounds read during
message processing, causing the process to crash and resulting in a
denial-of-service condition.
Published: 2026-07-30
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The GOOSE subscriber in libiec61850 fails to validate the UTC timestamp field in unauthenticated IEC 61850 GOOSE messages. A malicious message that contains an undersized timestamp field can trigger a heap out‑of‑bounds read, causing the process to crash. The resulting crash creates a denial‑of‑service condition. This weakness is classified as CWE‑125.

Affected Systems

MZ Automation GmbH’s libiec61850 library is affected. All releases prior to the recommended 1.6.2 update are vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity vulnerability. The EPSS score is < 1%, and the vulnerability is not in the CISA KEV catalog. A remote attacker who can inject crafted GOOSE frames onto the network can exploit the flaw without authentication, leading to service disruption.

Generated by OpenCVE AI on August 3, 2026 at 10:21 UTC.

Remediation

Vendor Solution

MZ Automation GmbH recommends that users update to version 1.6.2.


OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch to update libiec61850 to version 1.6.2
  • If patch deployment is delayed, block or filter IEC 61850 GOOSE traffic (EtherType 0x88B8) on the network perimeter to prevent malicious frames from reaching the subscriber
  • Monitor system logs for unexpected crashes or DDoS patterns that may indicate exploitation attempts

Generated by OpenCVE AI on August 3, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Mz-automation
Mz-automation libiec61850
Vendors & Products Mz-automation
Mz-automation libiec61850

Thu, 30 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Description The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition.
Title MZ Automation libiec61850 Out-of-bounds Read
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mz-automation Libiec61850
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-31T15:58:46.395Z

Reserved: 2026-07-27T19:32:49.387Z

Link: CVE-2026-66720

cve-icon Vulnrichment

Updated: 2026-07-31T15:58:40.866Z

cve-icon NVD

Status : Received

Published: 2026-07-30T23:16:53.830

Modified: 2026-07-31T16:17:10.990

Link: CVE-2026-66720

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:30:18Z

Weaknesses