Junglewise Threat Intelligence

CVE-2026-63550: MZ Automation GmbH libiec61850 heap out-of-bounds read in MMS BER decoder

CVE-2026-63550 · Severity: medium · CVSS 6.5 · Published 2026-07-30

Executive brief

A vulnerability exists in a library used for communication in energy and industrial control systems. An attacker with access to the network could send a specially crafted message to a device using this library, causing the communication service to crash. This results in a denial-of-service, potentially disrupting the monitoring or control of critical infrastructure.

Technical details

A heap out-of-bounds read vulnerability (CWE-125) exists in the MMS BER decoder of libiec61850. The flaw is located in the boundary-handling logic when processing specific fields within confirmed-request messages. An attacker can exploit this by sending a crafted BER-encoded element over an established MMS session (TCP port 102). This causes the decoder to incorrectly advance its internal read position, leading to an out-of-bounds read that crashes the MMS handling process. The vulnerability is addressed in version 1.6.2.

Affected products

  • MZ Automation GmbH libiec61850 < 1.6.2

Timeline

  • 2026-07-30: advisory: CISA ICSA-26-211-10 published
  • 2026-07-30: disclosed: CVE-2026-63550 published
  • 2026-07-30: patched: Vendor recommends updating to version 1.6.2

References