Description
The MMS BER decoder contains a flaw in decoding fixed-width BER fields
(boolean/integer): an attacker-supplied length value is not validated,
causing a read past the end of a heap buffer. This leads to termination
of the MMS service process and a denial-of-service condition.
(boolean/integer): an attacker-supplied length value is not validated,
causing a read past the end of a heap buffer. This leads to termination
of the MMS service process and a denial-of-service condition.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
MZ Automation GmbH recommends that users update to version 1.6.2.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 31 Jul 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mz-automation
Mz-automation libiec61850 |
|
| Vendors & Products |
Mz-automation
Mz-automation libiec61850 |
Thu, 30 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition. | |
| Title | MZ Automation libiec61850 Out-of-bounds Read | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-07-30T22:35:14.668Z
Reserved: 2026-07-27T19:32:49.396Z
Link: CVE-2026-65421
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-31T00:00:05Z
Weaknesses