BER-encoded request data. When an MMS confirmed request PDU containing
an extended BER tag is received over an established session, the decoder
may advance its internal buffer incorrectly due to a missing bounds
check. This results in a one byte heap out-of-bounds read and causes the
MMS service process to terminate, leading to a denial-of-service
condition.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
MZ Automation GmbH recommends that users update to version 1.6.2.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 03 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mz-automation
Mz-automation libiec61850 |
|
| Vendors & Products |
Mz-automation
Mz-automation libiec61850 |
Fri, 31 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing bounds check. This results in a one byte heap out-of-bounds read and causes the MMS service process to terminate, leading to a denial-of-service condition. | |
| Title | MZ Automation libiec61850 Out-of-bounds Read | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-07-31T15:54:00.925Z
Reserved: 2026-07-27T19:32:49.401Z
Link: CVE-2026-66349
Updated: 2026-07-31T15:53:56.350Z
Status : Received
Published: 2026-07-30T23:16:52.920
Modified: 2026-07-31T16:17:10.367
Link: CVE-2026-66349
No data.
OpenCVE Enrichment
Updated: 2026-08-03T15:45:03Z
-
CWE-125
Out-of-bounds Read