Junglewise Threat Intelligence

CVE-2026-19259: MZ Automation libiec61850 heap buffer overflow in MmsMapping

CVE-2026-19259 · Severity: medium · CVSS 5.3 · Published 2026-08-08

Technologies: MZ Automation libIEC61850. Vendors: MZ Automation.

Executive brief

MZ Automation libiec61850 is a library used by industrial control system (ICS) client applications to communicate with power grid and utility servers using the IEC 61850 protocol. A malicious or compromised server can send a specially crafted response that triggers a heap buffer overflow in the client, causing the application to crash and denying service to operators who rely on these systems for monitoring and control.

Technical details

The vulnerability is a heap buffer over-read in the MmsMapping_varAccessSpecToObjectReference function (src/iec61850/common/iec61850_common.c, line 876) triggered by a malformed GetNamedVariableListAttributesResponse.itemId field. The vulnerable code assumes that decoded MMS names follow an internal LN$FC$... format and performs fixed-offset reads relative to the first ' separator without validating the string length. When a malicious MMS server returns itemId="

quot; (two bytes: ' and null terminator), the conversion routine reads past the allocated heap buffer. The attack is client-side, reachable during normal protocol operation (dataset directory enumeration), and requires network connectivity to a malicious or MITM-compromised MMS server. An attacker can cause denial of service by crashing libiec61850-based client applications. The project has not yet responded to the early disclosure.

Affected products

  • MZ Automation libiec61850 up to 1.6.1

Timeline

  • 2026-08-08: disclosed: CVE-2026-19259 published
  • 2026-08-08: other: Exploit proof-of-concept available

References

Related threats