highOther

MZ Automation lib60870 Out-of-Bounds Read Denial of Service (CVE-2026-16002)

First seen Jul 26, 2026 · Updated Jul 26, 2026 · CVSS 8.2

ICSOTIEC-60870-5-104denial-of-serviceout-of-bounds-readCISA-advisorycritical-infrastructureprotocol-library

MZ Automation's lib60870 library, versions 2.4.0 and earlier, contains an out-of-bounds read vulnerability (CVE-2026-16002) in its IEC 60870-5-104 protocol parsing code. Remote, unauthenticated attackers can crash the parsing process, causing a denial of service in energy, water/wastewater, and chemical sector control systems that rely on this library for SCADA/ICS communications.

Technical Analysis

CVE-2026-16002 is an out-of-bounds read (CWE-125) in lib60870, an open-source implementation of the IEC 60870-5-101/104 protocols widely used for telecontrol and SCADA communications in critical infrastructure. The flaw resides in the message parsing routine and can be triggered remotely without authentication or user interaction, allowing an attacker to crash the parser and cause a denial of service condition affecting availability (CVSS v3.1: 8.2 HIGH, AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H; CVSS v4.0: 8.8 HIGH). No public exploitation has been reported as of the advisory date. This vulnerability primarily impacts industrial control systems and protocol gateways rather than AI agent infrastructure directly, though organizations running AI-driven monitoring or automation agents that ingest telemetry from IEC 60870-5-104 devices via lib60870-based gateways could experience pipeline disruption or data gaps if the parser crashes, indirectly degrading agent decision-making reliability in OT environments.

Affected Systems

MZ Automation lib60870 library versions <=2.4.0, used in IEC 60870-5-101/104 protocol implementations across ICS/SCADA deployments in energy, water/wastewater, and chemical sectors worldwide.

Indicators of Compromise

  • N/A - no known indicators of compromise; no public exploitation reported at time of advisory.

Remediation Steps

  1. 1

    Update lib60870

    Upgrade to lib60870 version 2.4.1 or later as recommended by MZ Automation.

  2. 2

    Network segmentation

    Isolate control system networks and devices behind firewalls, separating them from business/IT networks and the internet.

  3. 3

    Minimize network exposure

    Ensure ICS/SCADA devices using this library are not directly accessible from the internet.

  4. 4

    Secure remote access

    Use VPNs or other secure remote access mechanisms, keeping them patched and monitored.

  5. 5

    Monitor and report

    Monitor for abnormal parser crashes or communication failures and report suspected malicious activity to CISA.

CVE / Advisory IDs

CVE-2026-16002

Industries Most Exposed

EnergyWater and WastewaterChemicalCritical InfrastructureIndustrial Control Systems

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.