Executive brief
A vulnerability exists in lib60870, a software library used in industrial control systems for communication in the energy, chemical, and water sectors. An attacker can exploit this flaw to crash the software's data parsing process, leading to a denial of service. This could disrupt critical infrastructure operations and monitoring by causing communication failures between industrial devices.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in MZ Automation lib60870 versions 2.4.0 and prior. The flaw occurs during the parsing of network traffic, where the library may attempt to read data beyond the allocated buffer. A remote, unauthenticated attacker can exploit this by sending specially crafted packets to a system using the library. Successful exploitation results in a process crash (Denial of Service) and potentially limited information disclosure. The vendor has released version 2.4.1 to address this issue.
Affected products
- MZ Automation lib60870 <=2.4.0
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory: ICSA-26-204-07 published by CISA
- 2026-07-23: patched: Version 2.4.1 released