CVE-2026-66364

MEDIUM

MZ Automation libiec61850 Out-of-bounds Read

Title source: cna
STIX 2.1

Description

The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length, causing the parser to over read by one byte. This out-of-bounds read reliably terminates the subscriber process, resulting in a denial-of-service condition.

Scores

CVSS v3 6.5
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-125
Status published
Products (2)
MZ Automation GmbH/libiec61850 < 1.6.2
MZ Automation GmbH/libiec61850 1.6.2
Published Jul 30, 2026
Tracked Since Jul 31, 2026