MZ Automation lib60870

MonitorCVSS 6.5ICS-CERT ICSA-26-211-11Jul 30, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

MZ Automation lib60870 versions up to 2.4.0 contain an out-of-bounds read vulnerability (CWE-125) in IEC 60870-5-104 protocol message handling. A remote attacker can send a malformed protocol message that triggers a buffer over-read, causing the process to crash and interrupting device communication. The vulnerability affects any application or device that embeds this library for SCADA master station or RTU functionality.

What this means
What could happen
An attacker could crash a device running lib60870, disrupting communication with IEC 60870-5-104 SCADA systems. This could interrupt remote monitoring and control of critical infrastructure equipment like power distribution or water treatment systems.
Who's at risk
This affects operators of SCADA and telemetry systems that use the MZ Automation lib60870 library for IEC 60870-5-104 protocol communication. This includes power utilities, water/wastewater systems, and other utilities using RTUs, master stations, or SCADA applications built on this library.
How it could be exploited
An attacker on the network sends a specially crafted IEC 60870-5-104 protocol message to a device running the vulnerable lib60870 library. The library fails to validate the message properly, causing a buffer over-read that crashes the process handling that connection.
Prerequisites
  • Network access to the IEC 60870-5-104 port (typically TCP 2404)
  • No authentication required to send protocol messages
remotely exploitableno authentication requiredlow complexityaffects SCADA communication
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (1)
ProductAffected VersionsFix Status
lib60870: 2.4.02.4.0Fix available
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to the IEC 60870-5-104 port to authorized SCADA master stations only using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate lib60870 to version 2.4.1 or later
Long-term hardening
0/1
HARDENINGSegment IEC 60870-5-104 devices onto a separate network from untrusted systems
API: /api/v1/advisories/9ee00faf-a24e-4148-a79a-036221b5aca8

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.