MZ Automation GmbH libiec61850

MonitorCVSS 7.5ICS-CERT ICSA-26-211-10Jul 30, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

MZ Automation GmbH libiec61850 versions before 1.6.2 contain an out-of-bounds read vulnerability (CWE-125) in IEC 60870-5-104 protocol handling. Successful exploitation allows an attacker to cause a denial-of-service condition on affected devices by sending a specially crafted network packet. The vulnerability requires only network access and no authentication.

What this means
What could happen
An attacker with network access to a device running vulnerable libiec61850 could trigger a denial-of-service condition, causing the device to become unresponsive or crash and disrupting any industrial processes that depend on it.
Who's at risk
This affects any water authority, electric utility, or industrial facility running software or devices that embed MZ Automation GmbH's libiec61850 library, particularly SCADA systems, RTUs, and IEDs (Intelligent Electronic Devices) that use IEC 60870-5-104 protocol for remote communication and control.
How it could be exploited
An attacker sends a specially crafted network packet to the device running libiec61850 below version 1.6.2. The packet triggers an out-of-bounds read vulnerability (CWE-125) in the IEC 60870-5-104 protocol handler, causing the device to crash or become unresponsive. No authentication or user interaction is required.
Prerequisites
  • Network access to the device running libiec61850
  • Device running libiec61850 version earlier than 1.6.2
  • Network connectivity to the port where IEC 60870-5-104 communication occurs
remotely exploitableno authentication requiredlow complexityaffects availability (denial-of-service)
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
libiec61850<1.6.2No fix yet
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to devices running libiec61850 using firewall rules to allow only trusted engineering workstations and SCADA servers
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate libiec61850 to version 1.6.2 or later
Long-term hardening
0/1
HARDENINGSegment IEC 60870-5-104 communication to a dedicated industrial network isolated from untrusted networks
API: /api/v1/advisories/ed9470f7-c96d-46be-948f-7eb737c0789f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

MZ Automation GmbH libiec61850 | CVSS 7.5 - OTPulse