CVE-2026-66360: MZ Automation libiec61850 Out-of-bounds Read
The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap over read. This condition occurs before MMS session establishment, a crafted TCP/102 connection attempt can trigger the issue. The resulting over read causes the process to terminate, leading to a denial of service condition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MZ Automation libiec61850to a version that resolves this vulnerability.Fixed in 1.6.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66360?
The severity of CVE-2026-66360 is rated high with a score of 7.5.
What type of vulnerability is CVE-2026-66360?
CVE-2026-66360 is an out-of-bounds read vulnerability related to the handling of presentation data.
How do I fix CVE-2026-66360?
To fix CVE-2026-66360, ensure that you apply the latest security patches from MZ Automation for the LibIEC61850 software.
What software is affected by CVE-2026-66360?
CVE-2026-66360 affects MZ Automation's LibIEC61850 software.
What are the potential impacts of exploitation of CVE-2026-66360?
The exploitation of CVE-2026-66360 could lead to a bounded heap over read, potentially causing a denial of service condition.