CVE-2026-18583: mz-automation libiec61850 MMS Request mms_mapping.c checkDataSetAccess out-of-bounds
A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccess of the file src/iec61850/server/mmsmapping/mmsmapping.c of the component MMS Request Handler. This manipulation causes out-of-bounds read. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 1.6.2 is capable of addressing this issue. Patch name: 062062daf4cb50c7aa76e01d6fb4d58fc9278a7d. Upgrading the affected component is recommended. The vendor was contacted early about this disclosure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mz-automation libiec61850to a version that resolves this vulnerability.Fixed in 1.6.2Patch 062062daf4cb50c7aa76e01d6fb4d58fc9278a7d
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18583?
The severity of CVE-2026-18583 is rated as medium with a score of 5.3.
How do I fix CVE-2026-18583?
To fix CVE-2026-18583, update to mz-automation libiec61850 version 1.6.2 or later.
What is the impact of CVE-2026-18583?
CVE-2026-18583 can lead to out-of-bounds read vulnerabilities, potentially affecting system stability.
Is CVE-2026-18583 remotely exploitable?
Yes, CVE-2026-18583 can be exploited remotely due to its nature in the MMS Request Handler.
Which software is affected by CVE-2026-18583?
CVE-2026-18583 affects mz-automation libiec61850 versions up to 1.6.1.