MZ Automation GmbH libiec61850 Multiple Out-of-Bounds Read Vulnerabilities
First seen Aug 2, 2026 · Updated Aug 2, 2026 · CVSS 7.5
MZ Automation GmbH's libiec61850 library, widely used in industrial control systems for substation automation, contains eight out-of-bounds read vulnerabilities (CVE-2026-66720, 66369, 63550, 65421, 66364, 66349, 56758, 66360) in its GOOSE, MMS, ACSE, and ISO Presentation layer parsers. Successful exploitation via crafted network messages can crash affected processes, causing denial-of-service conditions on devices in energy sector control systems. No public exploitation has been reported; a patched version (1.6.2) is available.
Technical Analysis
The vulnerabilities stem from missing or incorrect bounds checks (CWE-125) across multiple protocol handlers in libiec61850: the GOOSE subscriber and payload parsers can be crashed via a single unauthenticated Layer-2 multicast frame (EtherType 0x88B8) with malformed timestamp or length fields; the MMS BER decoder and ACSE/ISO Presentation layer handlers can be crashed via crafted TCP/102 session traffic containing malformed BER-encoded fields, AARQ PDUs, or presentation-layer parameters. All flaws result in heap out-of-bounds reads that terminate the affected process, yielding denial-of-service; the highest-severity issue (CVE-2026-66360, CVSS v3.1 7.5) can be triggered pre-authentication during session negotiation. These are OT/ICS-specific vulnerabilities affecting substation automation gateways and IEDs rather than general-purpose IT infrastructure, so there is no direct AI agent system impact; however, organizations running AI-driven monitoring, anomaly-detection, or automation agents that interface with IEC 61850 substation networks should ensure such agents are not exposed to crafted GOOSE/MMS traffic paths that could disrupt the underlying control processes they depend on.
Affected Systems
MZ Automation GmbH libiec61850 versions prior to 1.6.2, used in IEC 61850-compliant substation automation devices, IEDs, and gateways in the energy sector worldwide.
Indicators of Compromise
- No specific IOCs published; exploitation involves crafted IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast frames and malformed MMS/ACSE/Presentation layer messages over TCP port 102.
Remediation Steps
- 1
Update libiec61850
Upgrade to libiec61850 version 1.6.2 or later, which addresses all eight vulnerabilities.
- 2
Network segmentation
Isolate control system networks and devices behind firewalls; ensure no direct internet accessibility for affected devices.
- 3
Restrict remote access
Use VPNs or other secure remote access methods when remote connectivity is required, and keep VPN software updated.
- 4
Monitor process bus traffic
Deploy monitoring for anomalous GOOSE multicast frames and malformed MMS/TCP 102 traffic to detect potential exploitation attempts.
- 5
Risk assessment
Perform impact analysis and risk assessment before deploying mitigations, per CISA guidance for ICS environments.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.