CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

MZ Automation GmbH libiec61850

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3575

As cited

Copy frozen at (site build).

vulnerabilities

MZ Automation GmbH libiec61850

MZ Automation GmbH libiec61850 versions prior to 1.6.2 contain eight out-of-bounds read vulnerabilities affecting the GOOSE subscriber and MMS (Manufacturing Message Specification) BER decoder components. These flaws allow unauthenticated attackers on the local network or authenticated users to craft specially formatted messages that crash the affected processes, resulting in denial-of-service conditions. The vendor recommends immediate updates to version 1.6.2 to remediate the issues.

Why it matters: Energy infrastructure operators and power systems integrators relying on libiec61850 for IEC 61850 GOOSE and MMS communications face process crashes and loss of control messaging from low-complexity network attacks, potentially disrupting real-time coordination on process buses worldwide.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

MZ Automation GmbH libiec61850

MZ Automation GmbH libiec61850 versions prior to 1.6.2 contain eight out-of-bounds read vulnerabilities affecting the GOOSE subscriber and MMS (Manufacturing Message Specification) BER decoder components. These flaws allow unauthenticated attackers on the local network or authenticated users to craft specially formatted messages that crash the affected processes, resulting in denial-of-service conditions. The vendor recommends immediate updates to version 1.6.2 to remediate the issues.

Why it matters: Energy infrastructure operators and power systems integrators relying on libiec61850 for IEC 61850 GOOSE and MMS communications face process crashes and loss of control messaging from low-complexity network attacks, potentially disrupting real-time coordination on process buses worldwide.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary