MZ Automation libIEC61850

Plan PatchCVSS 8.1ICS-CERT ICSA-26-204-06Jul 23, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

Multiple buffer overflow and memory safety vulnerabilities exist in libIEC61850 versions 1.0.0 through 1.6.1. These vulnerabilities allow unauthenticated network-adjacent attackers to crash IEC 61850 services or execute arbitrary code on affected devices. IEC 61850 is the standard protocol for communication between protection relays, intelligent electronic devices, and SCADA systems in electric utilities. Exploitation could disrupt protection functions, control visibility, and communication between critical grid devices.

What this means
What could happen
An attacker on your network could crash IEC 61850 communication services (used by protection relays and SCADA systems to exchange protection and control data) or execute arbitrary code on affected devices, disrupting real-time visibility of grid/process state and ability to issue control commands.
Who's at risk
Organizations operating IEC 61850 devices such as protection relays, intelligent electronic devices (IEDs), SCADA gateways, and engineering workstations in electric utilities and substations. This affects any system using the open-source libIEC61850 library in versions 1.0.0 through 1.6.1.
How it could be exploited
An attacker with network access to a device running vulnerable libIEC61850 (typically an engineering workstation, gateway, or protection relay) can send specially crafted IEC 61850 protocol messages without authentication. These messages trigger buffer overflows or other memory safety issues that crash the service or allow code execution with the privileges of the IEC 61850 process.
Prerequisites
  • Network access to port 102 (IEC 61850 standard port) or the port where libIEC61850 is listening
  • No authentication required
  • Device running vulnerable libIEC61850 version 1.0.0 through 1.6.1
remotely exploitableno authentication requiredlow complexityaffects protection systems and real-time control visibility
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (1)
ProductAffected VersionsFix Status
libIEC61850: >=v1.0.0|<=v1.6.1≥ v1.0.0|≤ v1.6.1Fix available
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to IEC 61850 services (port 102) to only authorized engineering workstations and SCADA/protection systems using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate libIEC61850 to the latest build available from https://github.com/mz-automation/libiec61850
Long-term hardening
0/1
HARDENINGSegment IEC 61850 devices and workstations onto a separate VLAN or network zone isolated from untrusted networks
API: /api/v1/advisories/4690375d-a6af-4126-acc9-b1491e51c014

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

MZ Automation libIEC61850 | CVSS 8.1 - OTPulse