PatchSiren

MZ Automation GmbH CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH MZ Automation GmbH CVE published 2026-07-30

CVE-2026-66720

The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition. This issue affects organizations us [truncated]

HIGH MZ Automation GmbH CVE published 2026-07-30

CVE-2026-66364

A boundary handling flaw in the GOOSE payload parser can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus, causing a denial-of-service condition. This vulnerability affects systems using the GOOSE payload parser, particularly in industries relying on process bus communication, such as critical infrastructure and manufacturing plants. The flaw allows an attacker-controlle [truncated]

MEDIUM MZ Automation GmbH CVE published 2026-07-30

CVE-2026-66349

A vulnerability exists in the MMS server connection handler, which processes BER-encoded request data. When an MMS confirmed request PDU with an extended BER tag is received over an established session, the decoder may incorrectly advance its internal buffer due to a missing bounds check. This results in a one-byte heap out-of-bounds read, causing the MMS service process to terminate and leading to a deni [truncated]

HIGH MZ Automation GmbH CVE published 2026-07-30

CVE-2026-65421

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T23:16:52.597Z and has not been modified since then. The vulnerability affects MMS BER decoder deployments. Organizations should prioritize patching this vulnerability to prevent potential denial-of-service conditions. The vulnerability class involves improper input validation. The likely operatio [truncated]

HIGH MZ Automation GmbH CVE published 2026-07-30

CVE-2026-63550

The MMS BER decoder contains a boundary-handling flaw in confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position incorrectly, leading to a heap out-of-bounds read and denial-of-service. Organizations should review MMS session configurations and apply patches or updates to MMS BER decoder i [truncated]

MEDIUM MZ Automation GmbH CVE published 2026-07-30

CVE-2026-56758

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T23:16:51.517Z and has not been modified since then. The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker-controlled length value of zero or one may cause the parser to read past the [truncated]