CVE-2026-65421: MZ Automation libiec61850 Out-of-bounds Read
The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MZ Automation libiec61850to a version that resolves this vulnerability.Fixed in 1.6.2 - Compensating control
Mitigate the denial-of-service condition by protecting the MMS service endpoint (MMS service process) with network-level controls (e.g., firewall/ACL/WAF/rate limiting) until the affected decoder issue is updated.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65421?
CVE-2026-65421 has a medium severity rating of 6.5.
What does CVE-2026-65421 affect?
CVE-2026-65421 affects the MZ Automation LibIEC61850 software due to an out-of-bounds read vulnerability.
How does CVE-2026-65421 impact systems?
CVE-2026-65421 can cause a denial-of-service condition by terminating the MMS service process.
How do I fix CVE-2026-65421?
To fix CVE-2026-65421, ensure that you update MZ Automation LibIEC61850 to the latest version that addresses this vulnerability.
What kind of attack does CVE-2026-65421 enable?
CVE-2026-65421 enables an attacker to exploit an unvalidated length value, potentially leading to denial-of-service.