Junglewise Threat Intelligence

CVE-2026-66720: MZ Automation GmbH libiec61850 heap out-of-bounds read in GOOSE subscriber

CVE-2026-66720 · Severity: medium · CVSS 6.5 · Published 2026-07-30

Executive brief

A vulnerability exists in a specialized communication library used in energy and industrial control systems. An attacker on the same local network could send a malicious message that causes the system to crash. This would result in a denial-of-service, potentially disrupting critical infrastructure operations and monitoring.

Technical details

The vulnerability is a heap out-of-bounds read (CWE-125) located within the GOOSE subscriber component of libiec61850. The root cause is improper validation of the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. An attacker can trigger this by sending a specially crafted GOOSE frame containing an undersized timestamp field. Successful exploitation allows an unauthenticated attacker on the adjacent network to crash the subscriber process, resulting in a denial-of-service (DoS) condition. The issue is resolved in version 1.6.2.

Affected products

  • MZ Automation GmbH libiec61850 < 1.6.2

Timeline

  • 2026-07-30: advisory
  • 2026-07-30: patched: Fixed in version 1.6.2

References