Junglewise Threat Intelligence

CVE-2026-66369: MZ Automation libiec61850 DoS in GOOSE parser

CVE-2026-66369 · Severity: medium · CVSS 6.5 · Published 2026-07-30

Executive brief

A vulnerability exists in a widely used library for industrial power grid communication. An attacker on the local network can send a single malicious message to crash the software responsible for monitoring electrical equipment. This results in a denial-of-service, potentially disrupting the visibility and control of critical energy infrastructure.

Technical details

An off-by-one boundary-handling flaw exists within the GOOSE parser component of libiec61850. The vulnerability is triggered when the parser incorrectly advances its internal buffer position while processing specific fields in a GOOSE message, leading to a heap out-of-bounds read (CWE-125). An unauthenticated attacker on the same Layer-2 network (process bus) can exploit this by sending a single crafted multicast frame. Successful exploitation reliably terminates the subscriber process, resulting in a denial-of-service. The issue is resolved in version 1.6.2.

Affected products

  • MZ Automation GmbH libiec61850 < 1.6.2

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory

References