CVE-2026-61893: MZ Automation lib60870 Out-of-bounds Read
A crafted IEC 60870-5-104 I-frame with TypeID 104 (CTSNA1) and an inflated object count causes TestCommandgetFromBuffer to read one byte past the end of the heap-allocated message buffer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MZ Automation lib60870to a version that resolves this vulnerability.Fixed in 2.4.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61893?
CVE-2026-61893 has a medium severity rating of 6.5 on the CVSS scale.
How do I fix CVE-2026-61893?
To mitigate CVE-2026-61893, ensure you are using the latest version of MZ Automation lib60870 that addresses this vulnerability.
What type of vulnerability is CVE-2026-61893?
CVE-2026-61893 is an out-of-bounds read vulnerability affecting MZ Automation lib60870.
What can be exploited in CVE-2026-61893?
CVE-2026-61893 can be exploited by sending a crafted IEC 60870-5-104 I-frame with an inflated object count.
What are the consequences of CVE-2026-61893?
The consequences of CVE-2026-61893 include potential information leakage due to reading past the end of a heap-allocated buffer.