CVE-2026-16002

MZ Automation · lib60870

The lib60870 library is vulnerable to an out-of-bounds read, potentially allowing an attacker to crash the parsing process and cause a denial of service.

Executive summary

An out-of-bounds read vulnerability in MZ Automation lib60870 allows unauthenticated remote attackers to trigger a denial of service condition.

Vulnerability

The library suffers from an out-of-bounds read during the parsing process. Exploitation can be achieved by an unauthenticated attacker over the network, resulting in application instability and service disruption.

Business impact

Successful exploitation results in a denial of service, which can impact systems relying on the lib60870 protocol implementation. With a CVSS score of 8.2, the risk to availability is high, particularly for industrial or critical infrastructure systems that utilize this library for communication.

Remediation

Immediate Action: Update the lib60870 library to version 2.4.1 or later as recommended by the vendor.

Proactive Monitoring: Monitor system logs for unexpected application crashes or service restarts that may indicate an attempt to exploit this parsing vulnerability.

Compensating Controls: Deploy network intrusion detection systems to identify and block malformed packets consistent with known protocol parsing attacks.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a significant availability risk to any system using the lib60870 library. It is imperative that organizations identify all instances of the affected software and apply the 2.4.1 update immediately to restore resilience against denial of service attacks.