Executive brief
MZ Automation libIEC61850 is a software library used in industrial control systems to implement communication protocols for power grid automation and energy infrastructure. A vulnerability in how the library handles specific data requests could allow an attacker to crash the server, leading to a loss of visibility and control over critical industrial processes. This disruption could impact operations in sectors such as energy, manufacturing, and transportation.
Technical details
A NULL pointer dereference (CWE-476) exists in the Manufacturing Message Specification (MMS) Write Named Variable List handler of libIEC61850. The vulnerability is triggered when the server receives a 'WriteRequest' containing an empty 'listOfData' field. An unauthenticated, network-adjacent or remote attacker (depending on network configuration) can exploit this to cause a crash of the service, resulting in a denial-of-service (DoS). The issue affects versions 1.0.0 through 1.6.1. Users are advised to update to the latest build from the vendor's repository to remediate the flaw.
Affected products
- MZ Automation libIEC61850 >=1.0.0, <=1.6.1
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory: Initial publication by CISA (ICSA-26-204-06)