highOther

MZ Automation GmbH libiec61850 Multiple Out-of-Bounds Read Vulnerabilities

First seen Aug 2, 2026 · Updated Aug 2, 2026 · CVSS 7.5

ICSOTdenial-of-serviceIEC61850GOOSEMMSout-of-bounds-readenergy-sectorCISA-advisory

MZ Automation GmbH's libiec61850 library, widely used in industrial control systems for substation automation, contains eight out-of-bounds read vulnerabilities (CVE-2026-66720, 66369, 63550, 65421, 66364, 66349, 56758, 66360) in its GOOSE, MMS, ACSE, and ISO Presentation layer parsers. Successful exploitation via crafted network messages can crash affected processes, causing denial-of-service conditions on devices in energy sector control systems. No public exploitation has been reported; a patched version (1.6.2) is available.

Technical Analysis

The vulnerabilities stem from missing or incorrect bounds checks (CWE-125) across multiple protocol handlers in libiec61850: the GOOSE subscriber and payload parsers can be crashed via a single unauthenticated Layer-2 multicast frame (EtherType 0x88B8) with malformed timestamp or length fields; the MMS BER decoder and ACSE/ISO Presentation layer handlers can be crashed via crafted TCP/102 session traffic containing malformed BER-encoded fields, AARQ PDUs, or presentation-layer parameters. All flaws result in heap out-of-bounds reads that terminate the affected process, yielding denial-of-service; the highest-severity issue (CVE-2026-66360, CVSS v3.1 7.5) can be triggered pre-authentication during session negotiation. These are OT/ICS-specific vulnerabilities affecting substation automation gateways and IEDs rather than general-purpose IT infrastructure, so there is no direct AI agent system impact; however, organizations running AI-driven monitoring, anomaly-detection, or automation agents that interface with IEC 61850 substation networks should ensure such agents are not exposed to crafted GOOSE/MMS traffic paths that could disrupt the underlying control processes they depend on.

Affected Systems

MZ Automation GmbH libiec61850 versions prior to 1.6.2, used in IEC 61850-compliant substation automation devices, IEDs, and gateways in the energy sector worldwide.

Indicators of Compromise

  • No specific IOCs published; exploitation involves crafted IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast frames and malformed MMS/ACSE/Presentation layer messages over TCP port 102.

Remediation Steps

  1. 1

    Update libiec61850

    Upgrade to libiec61850 version 1.6.2 or later, which addresses all eight vulnerabilities.

  2. 2

    Network segmentation

    Isolate control system networks and devices behind firewalls; ensure no direct internet accessibility for affected devices.

  3. 3

    Restrict remote access

    Use VPNs or other secure remote access methods when remote connectivity is required, and keep VPN software updated.

  4. 4

    Monitor process bus traffic

    Deploy monitoring for anomalous GOOSE multicast frames and malformed MMS/TCP 102 traffic to detect potential exploitation attempts.

  5. 5

    Risk assessment

    Perform impact analysis and risk assessment before deploying mitigations, per CISA guidance for ICS environments.

CVE / Advisory IDs

CVE-2026-66720CVE-2026-66369CVE-2026-63550CVE-2026-65421CVE-2026-66364CVE-2026-66349CVE-2026-56758CVE-2026-66360

Industries Most Exposed

EnergyCritical InfrastructureIndustrial Control Systems

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.