news.mlab.sh
Back to the feed
vulnerability

MZ Automation GmbH libiec61850

High
Summary

CISA has issued an advisory regarding multiple vulnerabilities in MZ Automation GmbH’s libiec61850 software, specifically version <1.6.2. These vulnerabilities, all related to out-of-bounds reads, can lead to denial-of-service conditions by exploiting flaws in the GOOSE subscriber, MMS BER decoder, ACSE layer, ISO Presentation layer, and MMS server connection handler. Users are strongly advised to update to version 1.6.2 to mitigate these risks. CISA recommends defensive measures such as network segmentation and secure remote access methods.

Read the full article at CISA Advisories

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.