CVE-2026-63033
View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed. The following versions of MZ Automation lib60870 are affected: lib60870 2.4.0 (CVE-2026-61893, CVE-2026-63033) CVSS Vendor Equipment Vulnerabilities v3 6.5 MZ Automation GmbH MZ Automation lib60870 Out-of-bounds Read Background Critical Infrastructure Sectors: Energy, Water and Wastewater, Critical Manufacturing, Chemical Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-61893 A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer. View CVE Details Affected Products MZ Automation lib60870 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH lib60870: 2.4.0 Product Status: known_affected Remediations Mitigation MZ Automation recommends users update to version 2.4.1 when available. Vendor fix See MZ Automation advisories for more information: https://github.com/mz-automation/lib60870/security/advisories/GHSA-g3w7-x5rx-83xm https://github.com/mz-automation/lib60870/security/advisories/GHSA-g3w7-x5rx-83xm Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L 4.0 6.9 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N CVE-2026-63033 A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer. View CVE Details Affected Products MZ Automation lib60870 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH lib60870: 2.4.0 Product Status: known_affected Remediations Mitigation MZ Automation recommends users update to version 2.4.1 when available. Vendor fix See MZ Automation advisory fo
CSIRTS triage
- What
- Vulnerabilities could crash the device being accessed.
- Who is affected
- Users of MZ Automation GmbH lib60870 version 2.4.0.
- Urgency
- Remediation is critical due to the potential for device crashes.
- Action
- Update lib60870 to a version later than 2.4.0.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-63033
Get an email if CVE-2026-63033 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
Advisory coverage (2)
- mediumCVE-2026-63033: A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU…nvd · 2026-07-30
- criticalMZ Automation lib60870cisa · 2026-07-30
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-63033)