Junglewise Threat Intelligence

CVE-2026-66360: MZ Automation libiec61850 out-of-bounds read in ISO Presentation layer

CVE-2026-66360 · Severity: high · CVSS 7.5 · Published 2026-07-30

Executive brief

A vulnerability exists in a specialized communication library used in energy and industrial automation systems. An attacker can send a specially crafted network request to a device using this library, causing the system to crash and become unavailable. This results in a denial-of-service condition that could disrupt critical infrastructure operations.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the ISO Presentation layer of libiec61850 due to a missing length check during normal mode negotiation. Specifically, the processing of encoded presentation data fails to validate attacker-controlled fields, where a zero-length value triggers a bounded heap over-read. This flaw can be exploited remotely via a crafted TCP port 102 connection attempt before an MMS session is even established. Successful exploitation causes the process to terminate, resulting in a denial-of-service (DoS) condition. The issue is resolved in version 1.6.2.

Affected products

  • MZ Automation GmbH libiec61850 < 1.6.2

Timeline

  • 2026-07-30: advisory: CISA ICSA-26-211-10 published
  • 2026-07-30: disclosed: CVE-2026-66360 published in NVD

References