VORANT. Threat Intelligence Sign in Get the full feed

MZ Automation lib60870 out-of-bounds read flaws

medium vulnerability energymanufacturing

Two out-of-bounds read vulnerabilities in MZ Automation's lib60870 IEC 60870-5-104 library could crash affected ICS devices; no active exploitation reported.

CISA published an ICS advisory detailing two out-of-bounds read vulnerabilities (CWE-125) in MZ Automation's lib60870 library version 2.4.0, which implements the IEC 60870-5-104 protocol widely used in energy, water/wastewater, critical manufacturing, and chemical sector control systems. Both flaws stem from insufficient validation of object counts in crafted I-frame messages: CVE-2026-61893 affects TestCommand_getFromBuffer when parsing a TypeID 104 (C_TS_NA_1) frame with an inflated object count, while CVE-2026-63033 affects InformationObject_ParseObjectAddress when a declared object count exceeds what fits in the ASDU body. In both cases, an attacker-crafted message causes a one-byte heap buffer over-read, which could crash the affected device.

The vulnerabilities were reported by a researcher from the Central Power Research Institute in Bengaluru, India. MZ Automation, headquartered in Germany, recommends upgrading to version 2.4.1 once available; CISA advises standard ICS network hardening practices including minimizing internet exposure, isolating control system networks behind firewalls, and using secure VPNs for remote access. CISA states no known public exploitation of these vulnerabilities has been reported at this time, indicating this is a proactive disclosure rather than an active threat.

Mentioned in this report

Vulnerabilities CVE-2026-61893CVE-2026-63033

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free