vulnerability
MZ Automation GmbH libiec61850
High
Summary
CISA has issued an advisory regarding multiple vulnerabilities in MZ Automation GmbH’s libiec61850 software, specifically version <1.6.2. These vulnerabilities, all related to out-of-bounds reads, can lead to denial-of-service conditions by exploiting flaws in the GOOSE subscriber, MMS BER decoder, ACSE layer, ISO Presentation layer, and MMS server connection handler. Users are strongly advised to update to version 1.6.2 to mitigate these risks. CISA recommends defensive measures such as network segmentation and secure remote access methods.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data