Security & Threat Intelligence · 23.07.2026, 18:07 UTC
MZ Automation lib60870
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA ICS Advisories · CISA Advisories ↗ |
| Veröffentlicht | 23.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-16002. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. The following versions of MZ Automation lib60870 are affected:
lib60870 <=2.4.0
CVSS Vendor Equipment Vulnerabilities
v3 8.2 MZ Automation MZ Automation lib60870 Out-of-bounds Read
Background
Critical Infrastructure Sectors: Chemical, Energy, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-16002
The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service. View CVE Details
Affected Products MZ Automation lib60870
Vendor:MZ Automation Product Version:MZ Automation lib60870: <=2.4.0 Product Status:known_affected
Remediations Vendor fixMZ automation recommends users update to version 2.4.1 or later. Documentation can be found at https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv.https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv
Relevant CWE: CWE-125 Out-of-bounds Read
Metrics
CVSS Version Base Score Base Severity Vector String
3.1 8.2 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
4.0 8.8 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
Acknowledgments
Lars Tray reported this vulnerability to CISA
Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy …