Junglewise Threat Intelligence

CVE-2026-66364: MZ Automation GmbH libiec61850 out-of-bounds read in GOOSE parser

CVE-2026-66364 · Severity: medium · CVSS 6.5 · Published 2026-07-30

Executive brief

A vulnerability exists in a specialized communication library used in energy infrastructure and industrial control systems. An attacker on the local network can send a single malicious message that crashes the system's communication service. This results in a denial-of-service, potentially disrupting the monitoring and control of power grid equipment.

Technical details

A boundary handling flaw exists in the GOOSE payload parser of libiec61850 before version 1.6.2. The vulnerability is triggered when an attacker-controlled inner element length exceeds its enclosing length within a Layer 2 multicast frame (EtherType 0x88B8). This leads to a one-byte heap out-of-bounds read (CWE-125). Exploitation reliably terminates the subscriber process, resulting in a denial-of-service condition. The attack requires no authentication but must be launched from the same local network segment (process bus). The issue is resolved in version 1.6.2.

Affected products

  • MZ Automation GmbH libiec61850 < 1.6.2

Timeline

  • 2026-07-30: advisory
  • 2026-07-30: disclosed

References