CISA

MZ Automation lib60870

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of these vulnerabilities could crash the device being accessed.

The following versions of MZ Automation lib60870 are affected:

lib60870 2.4.0 (CVE-2026-61893, CVE-2026-63033)

Vendor

Equipment

MZ Automation GmbH

MZ Automation lib60870

Out-of-bounds Read

Critical Infrastructure Sectors: Energy, Water and Wastewater, Critical Manufacturing, Chemical

Countries/Areas Deployed: Worldwide

Company Headquarters Location: Germany

A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.

MZ Automation lib60870

MitigationMZ Automation recommends users update to version 2.4.1 when available.

Relevant CWE: CWE-125 Out-of-bounds Read

Metrics

Base Score

Base Severity

Vector String

3.1

6.5

MEDIUM

4.0

6.9

MEDIUM

A crafted ...