MZ Automation libIEC61850
libIEC61850 is a widely used library for implementing IEC 61850 protocol communications in electrical substation automation devices. Versions 1.4 and earlier, as well as versions 1.5 up to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e, contain buffer overflow and null pointer dereference vulnerabilities (CWE-121, CWE-476). These flaws can be triggered by remote attackers sending malicious IEC 61850 protocol messages to affected devices, leading to denial of service or remote code execution without requiring credentials or user interaction.
- Network access to a device running vulnerable libIEC61850 (typically port 102 for IEC 61850 protocol)
- No authentication required
- Attack does not require any special configuration of the target device
Patching may require device reboot — plan for process interruption
/api/v1/advisories/fdaa5159-1bbc-49e8-8cea-1d43f081305dGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.