Successful exploitation of these vulnerabilities could crash the device being accessed.
The following versions of MZ Automation lib60870 are affected:
lib60870 2.4.0 (CVE-2026-61893, CVE-2026-63033)
Vendor
Equipment
MZ Automation GmbH
MZ Automation lib60870
Out-of-bounds Read
Critical Infrastructure Sectors: Energy, Water and Wastewater, Critical Manufacturing, Chemical
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.
MZ Automation lib60870
MitigationMZ Automation recommends users update to version 2.4.1 when available.
Relevant CWE: CWE-125 Out-of-bounds Read
Metrics
Base Score
Base Severity
Vector String
3.1
6.5
MEDIUM
4.0
6.9
MEDIUM
A crafted ...
Read the full advisory on CISA →