CVE-2026-56758

MEDIUM

MZ Automation libiec61850 Out-of-bounds Read

Title source: cna
STIX 2.1

Description

The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer.

Scores

CVSS v3 6.5
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-125
Status published
Products (2)
MZ Automation GmbH/libiec61850 < 1.6.2
MZ Automation GmbH/libiec61850 1.6.2
Published Jul 30, 2026
Tracked Since Jul 31, 2026