MZ Automation GmbH libiec61850
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device. The following versions of MZ Automation GmbH libiec61850 are affected: libiec61850 <1.6.2 (CVE-2026-66720, CVE-2026-66369, CVE-2026-63550, CVE-2026-65421, CVE-2026-66364, CVE-2026-66349, CVE-2026-56758, CVE-2026-66360) CVSS Vendor Equipment Vulnerabilities v3 7.5 MZ Automation GmbH MZ Automation GmbH libiec61850 Out-of-bounds Read Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-66720 The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH libiec61850: <1.6.2 Product Status: known_affected Remediations Mitigation MZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-66369 The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service. View CVE Details Affected Products
CSIRTS triage
- What
- Vulnerabilities could cause a denial-of-service condition on the device.
- Who is affected
- Users of MZ Automation GmbH libiec61850 versions prior to 1.6.2.
- Urgency
- Remediation is critical due to the potential for denial-of-service attacks.
- Action
- Update libiec61850 to version 1.6.2 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch libiec61850
Get an email when a new libiec61850 advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-667200.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-663690.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-635500.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2026-654210.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-663640.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-663490.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
- Low exploitation riskCVE-2026-567580.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
- Low exploitation riskCVE-2026-663600.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-66720 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66369 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63550 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65421 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66364 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66349 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56758 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66360 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-66720: The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated…nvd
- mediumCVE-2026-66369: The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a sing…nvd
- mediumCVE-2026-66364: The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single u…nvd
- highCVE-2026-66360: The ISO Presentation layer contains a flaw in the handling of specific parameters during norma…nvd
- mediumCVE-2026-66349: The MMS server connection handler contains a flaw in its processing of BER-encoded request dat…nvd
- mediumCVE-2026-65421: The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an a…nvd
- mediumCVE-2026-63550: The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields with…nvd
- mediumCVE-2026-56758: The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishm…nvd
More from CISA Cybersecurity Advisories
- criticalWatchfire Controller Software2026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalSchneider Electric IGSS2026-07-30
- criticalMikroTik RouterOS2026-07-30