Summary
Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device.
The following versions of MZ Automation GmbH libiec61850 are affected:
- libiec61850 <1.6.2 (CVE-2026-66720, CVE-2026-66369, CVE-2026-63550, CVE-2026-65421, CVE-2026-66364, CVE-2026-66349, CVE-2026-56758, CVE-2026-66360)
| CVSS | Vendor | Equipment | Vulnerabilities |
|---|---|---|---|
| v3 7.5 | MZ Automation GmbH | MZ Automation GmbH libiec61850 | Out-of-bounds Read |
Background
- Critical Infrastructure Sectors: Energy
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Germany
Vulnerabilities
CVE-2026-66720
The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition.
Affected Products
MZ Automation GmbH libiec61850
Vendor:
MZ Automation GmbH
Product Version:
MZ Automation GmbH libiec61850: <1.6.2
Product Status:
known_affected
Relevant CWE: CWE-125 Out-of-bounds Read
Metrics
CVE-2026-66369
The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service.
Affected Products
MZ Automation GmbH libiec61850
Vendor:
MZ Automation GmbH
Product Version:
MZ Automation GmbH libiec61850: <1.6.2
Product Status:
known_affected
Relevant CWE: CWE-125 Out-of-bounds Read
Metrics
CVE-2026-63550
The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position incorrectly, leading to a heap out-of-bounds read. This condition causes the MMS handling process to terminate unexpectedly, resulting in a denial-of-service.
Affected Products
MZ Automation GmbH libiec61850
Vendor:
MZ Automation GmbH
Product Version:
MZ Automation GmbH libiec61850: <1.6.2
Product Status:
known_affected
Relevant CWE: CWE-125 Out-of-bounds Read
Metrics
CVE-2026-65421
The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition.
Affected Products
MZ Automation GmbH libiec61850
Vendor:
MZ Automation GmbH
Product Version:
MZ Automation GmbH libiec61850: <1.6.2
Product Status:
known_affected
Relevant CWE: CWE-125 Out-of-bounds Read
Metrics
CVE-2026-66364
The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length, causing the parser to over read by one byte. This out-of-bounds read reliably terminates the subscriber process, resulting in a denial-of-service condition.
Affected Products
MZ Automation GmbH libiec61850
Vendor:
MZ Automation GmbH
Product Version:
MZ Automation GmbH libiec61850: <1.6.2
Product Status:
known_affected
Relevant CWE: CWE-125 Out-of-bounds Read
Metrics
CVE-2026-66349
The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing bounds check. This results in a one byte heap out-of-bounds read and causes the MMS service process to terminate, leading to a denial-of-service condition.
Affected Products
MZ Automation GmbH libiec61850
Vendor:
MZ Automation GmbH
Product Version:
MZ Automation GmbH libiec61850: <1.6.2
Product Status:
known_affected
Relevant CWE: CWE-125 Out-of-bounds Read
Metrics
CVE-2026-56758
The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer.
Affected Products
MZ Automation GmbH libiec61850
Vendor:
MZ Automation GmbH
Product Version:
MZ Automation GmbH libiec61850: <1.6.2
Product Status:
known_affected
Relevant CWE: CWE-125 Out-of-bounds Read
Metrics
CVE-2026-66360
The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap over read. This condition occurs before MMS session establishment, a crafted TCP/102 connection attempt can trigger the issue. The resulting over read causes the process to terminate, leading to a denial of service condition.
Affected Products
MZ Automation GmbH libiec61850
Vendor:
MZ Automation GmbH
Product Version:
MZ Automation GmbH libiec61850: <1.6.2
Product Status:
known_affected
Relevant CWE: CWE-125 Out-of-bounds Read
Metrics
Acknowledgments
- Arun Babu of Central Power Research Institute reported these vulnerabilities to CISA
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
Locate control system networks and remote devices behind firewalls and isolating them from business networks.
When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves from social engineering attacks:
Do not click web links or open attachments in unsolicited email messages.
Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
Revision History
- Initial Release Date: 2026-07-30
| Date | Revision | Summary |
|---|---|---|
| 2026-07-30 | 1 | Initial Publication |