news.mlab.sh
Back to the feed
vulnerability

MZ Automation lib60870

Medium
Summary

A vulnerability in MZ Automation lib60870, version 2.4.0 and earlier, allows for a denial-of-service attack through an out-of-bounds read. This affects critical infrastructure sectors like chemical, energy, and water/wastewater. MZ Automation recommends updating to version 2.4.1 or later.

A vulnerability exists in MZ Automation lib60870, specifically versions 2.4.0 and below. This vulnerability is an out-of-bounds read that can be exploited to cause the parsing process to crash, resulting in a denial-of-service. The affected product is used within critical infrastructure sectors including chemical, energy, and water/wastewater facilities. MZ Automation GmbH, based in Germany, recommends that users update to version 2.4.1 or later to address this issue. CISA advises organizations to minimize network exposure for control system devices and isolate them from business networks when possible, utilizing secure remote access methods like VPNs.

Read the full article at CISA Advisories