CVE-2026-66720: MZ Automation libiec61850 Out-of-bounds Read
The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MZ Automation GmbH libiec61850to a version that resolves this vulnerability.Fixed in 1.6.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66720?
The severity of CVE-2026-66720 is medium, rated at 6.5.
What type of vulnerability is CVE-2026-66720?
CVE-2026-66720 is an out-of-bounds read vulnerability affecting the GOOSE subscriber component.
How does CVE-2026-66720 affect MZ Automation LibIEC61850?
CVE-2026-66720 can lead to a heap out-of-bounds read when processing improperly formatted GOOSE multicast messages.
How can I mitigate CVE-2026-66720?
Mitigation for CVE-2026-66720 involves ensuring that GOOSE message formats are properly validated and using updated versions of the software.
Is CVE-2026-66720 exploitable remotely?
Yes, CVE-2026-66720 is potentially exploitable remotely due to the nature of Layer-2 multicast messages.