Libiec61850 flaws enable IEC 61850 DoS attacks
Eight unpatched CVEs in MZ Automation's libiec61850 let attackers crash GOOSE/MMS substation automation processes with a single malformed packet.
CISA published an ICS advisory covering eight denial-of-service vulnerabilities in MZ Automation GmbH's libiec61850 library, versions prior to 1.6.2. The flaws span multiple protocol-handling components used in IEC 61850 substation automation: the GOOSE subscriber and payload parsers, the MMS BER decoder, the MMS server connection handler, the ACSE layer, and the ISO Presentation layer. All eight are out-of-bounds read issues (CWE-125) triggerable by a single crafted, often unauthenticated, packet—either a Layer-2 GOOSE multicast frame or a TCP/102 MMS/ISO session—causing the affected process to crash.
Because GOOSE messages are unauthenticated by design and MMS/ISO sessions run over a well-known port, an attacker with network access to a substation's process bus or station bus could remotely terminate protection or automation processes, disrupting monitoring and control functions in energy-sector environments. Libiec61850 is deployed worldwide in industrial control and substation automation products, so the exposure is broad but requires network reachability to the affected device—CISA's standard guidance to isolate ICS networks and avoid internet exposure substantially reduces risk.
MZ Automation has released version 1.6.2 to remediate all eight issues. CISA states no public exploitation of these vulnerabilities has been reported. The vulnerabilities were responsibly disclosed by a researcher at the Central Power Research Institute.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free