CVE-2026-63550: MZ Automation libiec61850 Out-of-bounds Read
The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position incorrectly, leading to a heap out-of-bounds read. This condition causes the MMS handling process to terminate unexpectedly, resulting in a denial-of-service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MZ Automation libiec61850to a version that resolves this vulnerability.Fixed in 1.6.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63550?
CVE-2026-63550 has a medium severity rating of 6.5.
How do I fix CVE-2026-63550?
To mitigate CVE-2026-63550, update to the latest version of MZ Automation LibIEC61850 that addresses the out-of-bounds read vulnerability.
What is the risk associated with CVE-2026-63550?
CVE-2026-63550 carries a risk factor of 38, indicating it poses a potential threat to system integrity.
What causes the vulnerability in CVE-2026-63550?
CVE-2026-63550 is caused by a boundary-handling flaw in the MMS BER decoder when processing confirmed-request messages.
Which software is affected by CVE-2026-63550?
CVE-2026-63550 affects the MZ Automation LibIEC61850 software.