MZ Automation lib60870
Plan PatchCVSS 8.2ICS-CERT ICSA-26-204-07Jul 23, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
lib60870 versions 2.4.0 and earlier contain an out-of-bounds read vulnerability (CWE-125) in the IEC 60870-5-104 protocol parser. Successful exploitation causes the parsing process to crash, resulting in denial of service and disruption of IEC 60870-5-104 communication between master and slave devices.
What this means
What could happen
An attacker can crash the parsing process in lib60870, causing denial of service and stopping communication with connected IEC 60870-5-104 systems, which could disrupt power distribution or water management SCADA operations.
Who's at risk
This affects utilities and operators running SCADA master stations, RTUs, or middleware that use the open-source lib60870 library to communicate via IEC 60870-5-104 protocol. Common deployments include power distribution control centers, water treatment SCADA systems, and any device acting as a master or slave in an IEC 60870-5-104 network.
How it could be exploited
An attacker sends a specially crafted IEC 60870-5-104 message over the network to a system running vulnerable lib60870. The library's parser encounters an out-of-bounds read condition and crashes, halting all protocol communication until the process restarts.
Prerequisites
- Network access to the port where lib60870 is listening (typically port 2404 for IEC 60870-5-104)
- lib60870 version 2.4.0 or earlier must be deployed and active
remotely exploitableno authentication requiredlow complexityaffects SCADA communication
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (1)
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate lib60870 to version 2.4.1 or later
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/d42dbe9e-5215-495f-8b3f-9830069f380bGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.