PatchSiren

MZ Automation CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW MZ Automation CVE published 2026-08-06

CVE-2026-19108

The CVE-2026-19108 vulnerability is identified in the deleteDataSetValuesShadowBuffer function of libiec61850 up to version 1.6.1, leading to a use-after-free issue. This vulnerability has a local attack vector, and its exploitation could impact system integrity. The CVE record, published on 2026-08-06T22:16:55.057Z, has not undergone any modifications. Users of libiec61850 up to version 1.6.1, particular [truncated]

CRITICAL mz-automation CVE published 2026-08-06

CVE-2026-67873

A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the current ASDU frame before encoding object fields and segment data. This vulnerability affects systems using lib60870-C 2.4.0, pa [truncated]

MEDIUM mz-automation CVE published 2026-08-03

CVE-2026-18582

A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Reporting_RCBWriteAccessHandler of the file src/iec61850/server/mms_mapping/reporting.c of the component Report Sending Path Handler. The manipulation results in free of memory not on the heap. It is possible to launch the attack remotely. The exploit has been released to the public and ma [truncated]

CRITICAL MZ Automation CVE published 2026-07-31

CVE-2026-52134

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T22:17:02.437Z and has not been modified since then. The libiec61850 v1.6 has an issue in the parseGoosePayload() function, which allows attackers to bypass authentication via a captured GOOSE frame. This vulnerability affects libiec61850 v1.6, particularly in critical infrastructure or industrial [truncated]

MEDIUM MZ Automation CVE published 2026-07-30

CVE-2026-63033

A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer. This vulnerability exists in IEC 60870-5-104 protocol implementations, particularly in industrial control systems, and could lead to information disclosure or system crash. The affected product co [truncated]

MEDIUM MZ Automation CVE published 2026-07-23

CVE-2026-50103

A NULL pointer dereference vulnerability exists in the L2 GOOSE and R-GOOSE shared parser of MZ Automation libIEC61850. This issue may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Organizations should prioritize updating to the latest build to mitig [truncated]

HIGH MZ Automation CVE published 2026-07-23

CVE-2026-50039

The MZ Automation libIEC61850 product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause memory corruption via a ReadRequest. This vulnerability has a CVSS score of 7.5 and is considered HIGH severity. Organizations using MZ Automation libIEC61850 in their industrial control systems should be aware of this vulnerability and take steps to mitigate it. The CVE record was pu [truncated]

HIGH MZ Automation CVE published 2026-07-23

CVE-2026-50032

A NULL pointer dereference vulnerability in MZ Automation libIEC61850, specifically in the MMS Write Named Variable List handler, may allow a network-adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field. This issue affects industrial control systems using MZ Automation libIEC61850 versions from 1.0.0 to 1.6.1. The vulnerability has a CVSS score of 7.5 and is consi [truncated]