CVE-2026-63033: MZ Automation lib60870 Out-of-bounds Read
A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObjectParseObjectAddress to read one byte past the end of the heap-allocated message buffer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MZ Automation lib60870to a version that resolves this vulnerability.Fixed in 2.4.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63033?
The severity of CVE-2026-63033 is medium with a score of 6.5.
What is CVE-2026-63033?
CVE-2026-63033 refers to an out-of-bounds read vulnerability in MZ Automation's lib60870 that can be triggered by a crafted IEC 60870-5-104 I-frame.
How do I fix CVE-2026-63033?
To fix CVE-2026-63033, ensure that you are using the latest version of MZ Automation lib60870 that addresses this vulnerability.
What causes CVE-2026-63033?
CVE-2026-63033 is caused by an IEC 60870-5-104 I-frame with a declared object count that exceeds the capacity of the ASDU body.
What are the potential impacts of CVE-2026-63033?
The potential impact of CVE-2026-63033 includes the possibility of reading past the end of a heap-allocated buffer, which could lead to information leakage.