CVE-2026-19259
- EPSS 0.12%
- Veröffentlicht 08.08.2026 06:00:09
- Zuletzt bearbeitet 12.08.2026 20:59:21
A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping_varAccessSpecToObjectReference of the file src/iec61850/common/iec61850_common.c of the component MMS Protocol Workflow. Such man...
CVE-2026-19206
- EPSS 0.16%
- Veröffentlicht 07.08.2026 13:45:12
- Zuletzt bearbeitet 12.08.2026 21:00:37
A security flaw has been discovered in MZ Automation libiec61850 up to 1.6.1. This affects the function SVReceiver_stopThreadless of the file src/sampled_values/sv_subscriber.c of the component ASDU Element Handler. Performing a manipulation results ...
CVE-2026-19108
- EPSS 0.12%
- Veröffentlicht 06.08.2026 22:16:55
- Zuletzt bearbeitet 12.08.2026 21:00:37
A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file src/iec61850/server/mms_mapping/reporting.c of the component URCB Revalidation. The manipulation resu...
CVE-2026-18583
- EPSS 0.5%
- Veröffentlicht 03.08.2026 04:15:08
- Zuletzt bearbeitet 12.08.2026 21:00:37
A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping.c of the component MMS Request Handler. This manipulation causes out-o...
CVE-2026-18582
- EPSS 0.5%
- Veröffentlicht 03.08.2026 01:15:12
- Zuletzt bearbeitet 12.08.2026 21:00:37
A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Reporting_RCBWriteAccessHandler of the file src/iec61850/server/mms_mapping/reporting.c of the component Report Sending Path Handler...
CVE-2026-50032
- EPSS 0.26%
- Veröffentlicht 23.07.2026 20:53:36
- Zuletzt bearbeitet 30.07.2026 14:12:18
A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.
CVE-2026-50103
- EPSS 0.17%
- Veröffentlicht 23.07.2026 20:50:42
- Zuletzt bearbeitet 30.07.2026 14:12:18
A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value.
CVE-2026-49035
- EPSS 0.37%
- Veröffentlicht 23.07.2026 20:48:18
- Zuletzt bearbeitet 30.07.2026 14:12:18
The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where A...
CVE-2026-50039
- EPSS 0.27%
- Veröffentlicht 23.07.2026 20:32:30
- Zuletzt bearbeitet 30.07.2026 14:12:18
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a Read Request.
CVE-2024-45970
- EPSS 0.6%
- Veröffentlicht 15.11.2024 19:15:07
- Zuletzt bearbeitet 01.10.2025 17:45:49
Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via the MMS FileDirResponse message.