Security & Threat Intelligence · 30.07.2026, 17:34 UTC
MZ Automation lib60870
| Schweregrad | info |
|---|---|
| CVE | ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories ↗ |
| Veröffentlicht | 30.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-61893, CVE-2026-63033. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed. The following versions of MZ Automation lib60870 are affected:
lib60870 2.4.0 (CVE-2026-61893, CVE-2026-63033)
CVSS Vendor Equipment Vulnerabilities
v3 6.5 MZ Automation GmbH MZ Automation lib60870 Out-of-bounds Read
Background
Critical Infrastructure Sectors: Energy, Water and Wastewater, Critical Manufacturing, Chemical Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-61893
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer. View CVE Details
Affected Products MZ Automation lib60870
Vendor:MZ Automation GmbH Product Version:MZ Automation GmbH lib60870: 2.4.0 Product Status:known_affected
Remediations MitigationMZ Automation recommends users update to version 2.4.1 when available. Vendor fixSee MZ Automation advisories for more information: https://github.com/mz-automation/lib60870/security/advisories/GHSA-g3w7-x5rx-83xmhttps://github.com/mz-automation/lib60870/security/advisories/GHSA-g3w7-x5rx-83xm
Relevant CWE: CWE-125 Out-of-bounds Read
Metrics
CVSS Version Base Score Base Severity Vector String
3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
4.0 6.9 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
CVE-2026-63033
A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body …