CVE-2026-66364: MZ Automation libiec61850 Out-of-bounds Read
The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length, causing the parser to over read by one byte. This out-of-bounds read reliably terminates the subscriber process, resulting in a denial-of-service condition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MZ Automation GmbHto a version that resolves this vulnerability.Fixed in 1.6.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66364?
The severity of CVE-2026-66364 is medium with a score of 6.5.
How does CVE-2026-66364 affect MZ Automation LibIEC61850?
CVE-2026-66364 exposes MZ Automation LibIEC61850 to an out-of-bounds read due to a boundary handling flaw in the GOOSE payload parser.
What are the potential impacts of CVE-2026-66364?
An attacker can exploit CVE-2026-66364 to cause application crashes or unexpected behavior by sending unauthenticated Layer 2 multicast frames.
How can I mitigate CVE-2026-66364?
To mitigate CVE-2026-66364, it is recommended to update to the latest version of MZ Automation LibIEC61850 that addresses this vulnerability.
Who is vulnerable to CVE-2026-66364?
Organizations using vulnerable versions of MZ Automation LibIEC61850 are at risk of exploiting CVE-2026-66364.