what fits in the ASDU body causes InformationObject_ParseObjectAddress
to read one byte past the end of the heap-allocated message buffer.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
MZ Automation recommends users update to version 2.4.1 when available. See MZ Automation advisory for more information: https://github.com/mz-automation/lib60870/security/advisories/GHSA-7v97-jmwv-w5j7
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 31 Jul 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mz-automation
Mz-automation lib60870 |
|
| Vendors & Products |
Mz-automation
Mz-automation lib60870 |
Thu, 30 Jul 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer. | |
| Title | MZ Automation lib60870 Out-of-bounds Read | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-07-30T22:54:25.681Z
Reserved: 2026-07-16T22:10:53.026Z
Link: CVE-2026-63033
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-31T00:30:18Z