ctipilot.ch

MZ Automation libIEC61850 stack-based buffer overflow via crafted ReadRequest (CVSS 3.1 7.5 / 4.0 8.7)

cve · CVE-2026-50039 single-source-national-cert

Coverage timeline
1
first 2026-07-24 → last 2026-07-24
Peak priority
notable
1 notable
Sources cited
2
1 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
4
see Related entities below
ATT&CK techniques
1
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques
Affected products
MZ Automation lib60870MZ Automation libIEC61850

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-24/mz-automation-libiec61850-lib60870-ot-preauth-rce · ATT&CK page ↗

Story timeline

  1. 2026-07-24MZ Automation libIEC61850: unauthenticated heap-overflow RCE via crafted MMS Initiate (CVE-2026-49035) plus four sibling OT-library flaws
    trending-vulnerabilitiesA pre-auth RCE in the widely-embedded libIEC61850 substation library — energy and water OEMs, not a single product, are affected

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • cisa.gov2 (100%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about MZ Automation libIEC61850 stack-based buffer overflow via crafted ReadRequest (CVSS 3.1 7.5 / 4.0 8.7) (1)

2026-07-24 · view entry permalink →

NOTABLECVE-2026-49035 +4NATOA2

MZ Automation libIEC61850: unauthenticated heap-overflow RCE via crafted MMS Initiate (CVE-2026-49035) plus four sibling OT-library flaws

CISA advisory ICSA-26-204-06 (2026-07-23) discloses four vulnerabilities in MZ Automation's open-source libIEC61850 (versions 1.0.0 through 1.6.1), a C library implementing the IEC 61850 MMS/GOOSE substation-automation protocols and embedded as an OEM component in energy-sector protection, control and monitoring equipment worldwide (CISA, 2026-07-23). The most severe, CVE-2026-49035 (CWE-122 heap-based buffer overflow, CVSS 3.1 8.1 / CVSS 4.0 9.2), is triggered by a crafted MMS Initiate request with no authentication and no user interaction; CISA states remote code execution has been demonstrated where ASLR is disabled, degrading to memory corruption or denial of service where it is enabled (CISA, 2026-07-23). The three companion flaws are a stack overflow via a crafted ReadRequest (CVE-2026-50039), and two null-pointer-dereference DoS conditions — one in the shared L2 GOOSE/R-GOOSE parser via a malformed TLV (CVE-2026-50103), one in the MMS Write Named Variable List handler via a WriteRequest with an empty listOfData field (CVE-2026-50032). A companion advisory, ICSA-26-204-07, covers the sibling lib60870 library (versions ≤ 2.4.0, implementing IEC 60870-5-104 SCADA telecontrol used in chemical, energy and water/wastewater sectors) with an out-of-bounds-read parser-crash DoS, CVE-2026-16002 (CISA, 2026-07-23). CISA reports no known public exploitation of any of the five.

The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.

No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.

CISA (ICSA-26-204-06) 2026-07-23
vulnerability24 Jul 04:36Zsingle-source · national CERTOpen finding ↗