2026-07-24 · view entry permalink →
MZ Automation libIEC61850: unauthenticated heap-overflow RCE via crafted MMS Initiate (CVE-2026-49035) plus four sibling OT-library flaws
CISA advisory ICSA-26-204-06 (2026-07-23) discloses four vulnerabilities in MZ Automation's open-source libIEC61850 (versions 1.0.0 through 1.6.1), a C library implementing the IEC 61850 MMS/GOOSE substation-automation protocols and embedded as an OEM component in energy-sector protection, control and monitoring equipment worldwide (CISA, 2026-07-23). The most severe, CVE-2026-49035 (CWE-122 heap-based buffer overflow, CVSS 3.1 8.1 / CVSS 4.0 9.2), is triggered by a crafted MMS Initiate request with no authentication and no user interaction; CISA states remote code execution has been demonstrated where ASLR is disabled, degrading to memory corruption or denial of service where it is enabled (CISA, 2026-07-23). The three companion flaws are a stack overflow via a crafted ReadRequest (CVE-2026-50039), and two null-pointer-dereference DoS conditions — one in the shared L2 GOOSE/R-GOOSE parser via a malformed TLV (CVE-2026-50103), one in the MMS Write Named Variable List handler via a WriteRequest with an empty listOfData field (CVE-2026-50032). A companion advisory, ICSA-26-204-07, covers the sibling lib60870 library (versions ≤ 2.4.0, implementing IEC 60870-5-104 SCADA telecontrol used in chemical, energy and water/wastewater sectors) with an out-of-bounds-read parser-crash DoS, CVE-2026-16002 (CISA, 2026-07-23). CISA reports no known public exploitation of any of the five.
The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.