Stack-based Buffer Overflow in MZ Automation libIEC61850
Published Jul 23, 2026
9.2
CRITICALCVSS 4.0
EPSS 0.61%
Description
The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.
Affected products
-
- Version 1.0.0StatusaffectedConstraints<=1.6.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| MZ Automation | libIEC61850 | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850. https://github.com/mz-automation/libiec61850
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48430 Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06 government-resource
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48430 | Advisory | |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06 | government-resource |
Change history (0)
No recorded changes yet.