CVE-2026-49035
MZ Automation · libIEC61850
The libIEC61850 library is susceptible to a heap-based buffer overflow, which can be triggered by a specially crafted MMS Initiate request.
Executive summary
A heap-based buffer overflow in the MZ Automation libIEC61850 library poses a high-severity risk of system instability or unauthorized code execution.
Vulnerability
This is a heap-based buffer overflow vulnerability (CWE-122) occurring during the processing of MMS Initiate requests. The vulnerability is exploitable by unauthenticated remote attackers, though it requires specific conditions to be met.
Business impact
Successful exploitation of this vulnerability could lead to significant system disruption or potential code execution in the context of the affected application. Given the CVSS score of 8.1, the vulnerability represents a high risk to operational environments, particularly those relying on industrial communication standards.
Remediation
Immediate Action: Update to the latest build of the libIEC61850 library as provided by MZ Automation.
Proactive Monitoring: Monitor network traffic for malformed MMS packets or unexpected application behavior that may indicate an attempt to trigger the overflow.
Compensating Controls: Deploy network intrusion detection systems configured to identify and block non-compliant or suspicious MMS traffic patterns.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Security teams should prioritize updating the libIEC61850 library to the latest available version. Implementing network-level filtering for industrial protocols is recommended to reduce the attack surface while the update process is completed.