CVE-2026-56758: MZ Automation libiec61850 Out-of-bounds Read
The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MZ Automation libiec61850to a version that resolves this vulnerability.Fixed in 1.6.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56758?
CVE-2026-56758 has a medium severity rating of 6.5.
What does the vulnerability CVE-2026-56758 affect?
CVE-2026-56758 affects the MZ Automation libiec61850 library.
What type of security risk is associated with CVE-2026-56758?
CVE-2026-56758 is associated with an out-of-bounds read vulnerability.
How can I mitigate CVE-2026-56758?
Mitigation for CVE-2026-56758 includes updating to the latest version of libiec61850 where the vulnerability is addressed.
What are the potential impacts of exploiting CVE-2026-56758?
Exploiting CVE-2026-56758 may lead to unauthorized access or denial of service through heap buffer over-read.