Junglewise Threat Intelligence

CVE-2026-50103: MZ Automation libIEC61850 NULL pointer dereference in GOOSE parser

CVE-2026-50103 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Executive brief

A vulnerability exists in a specialized software library used by industrial control systems in the energy and manufacturing sectors to communicate over power grid protocols. An attacker on the same local network can send a specially crafted message to crash applications that rely on this library for monitoring or control. This could lead to a loss of visibility or control over critical infrastructure equipment, potentially disrupting operations.

Technical details

The vulnerability is a NULL pointer dereference (CWE-228/CWE-476) within the shared parser for Layer 2 GOOSE and Routable GOOSE (R-GOOSE) protocols in libIEC61850. The flaw is triggered when the parser encounters a malformed Type-Length-Value (TLV) structure in a crafted GOOSE frame. An unauthenticated attacker located on the same network segment (adjacent) can exploit this to cause a denial-of-service (DoS) condition by crashing the subscribing application. The issue affects versions 1.0.0 through 1.6.1; users are advised to update to the latest build from the vendor's repository.

Affected products

  • MZ Automation libIEC61850 >=v1.0.0, <=v1.6.1

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References

Related threats