Sceawere

Vulnerability Detail

CVE-2026-19259UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

libiec61850 Heap Buffer Overflow Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
7h ago
Vendor
MZ Automation
Product
libiec61850
Attack Type
Heap-based Buffer Overflow
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping_varAccessSpecToObjectReference of the file src/iec61850/common/iec61850_common.c of the component MMS Protocol Workflow. Such manipulation of the argument GetNamedVariableListAttributesResponse.itemId leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-08T07:17:11.560Z",
  "pubdate": "2026-08-08T07:17:11.560Z",
  "executiveSummary": "A heap-based buffer overflow vulnerability has been identified in the MZ Automation libiec61850 library up to version 1.6.1, specifically within the MMS Protocol Workflow component. The vulnerability resides in the function MmsMapping_varAccessSpecToObjectReference located in src/iec61850/common/iec61850_common.c. Improper handling of the GetNamedVariableListAttributesResponse.itemId argument during MMS mapping operations allows an attacker to trigger a heap-based buffer overflow. Successful exploitation of this flaw can result in memory corruption, potentially leading to arbitrary code execution or denial of service conditions within the targeted application context. The attack vector requires local access to the system to carry out the exploitation. Public disclosure of the exploit increases the risk of malicious utilization, particularly given that the vendor has not yet responded to initial issue reports regarding the flaw. Organizations utilizing affected versions of the library face elevated operational and security risks until proper remediation measures are applied.",
  "technicalDetails": "The vulnerability is classified as a heap-based buffer overflow stemming from insufficient bounds checking and input validation within the MMS Protocol Workflow component of the MZ Automation libiec61850 library. The specific flaw exists in the function MmsMapping_varAccessSpecToObjectReference inside the source file src/iec61850/common/iec61850_common.c. During the processing of Manufacturing Message Specification (MMS) protocol workflows, specifically when handling the GetNamedVariableListAttributesResponse.itemId argument, the application fails to adequately verify the size of the input data relative to the allocated destination buffer on the heap.\nExploitation of this vulnerability requires local access to the vulnerable system. An attacker able to manipulate or supply a crafted GetNamedVariableListAttributesResponse.itemId argument can force the MmsMapping_varAccessSpecToObjectReference function to write data past the boundaries of the allocated heap buffer. The attack flow initiates when the vulnerable function processes the oversized or maliciously formatted itemId parameter. As the data is copied or mapped into memory without proper length restrictions, adjacent heap structures are overwritten.\nThe affected software versions include all releases of MZ Automation libiec61850 up to and including version 1.6.1. Depending on the memory layout and the specific data written during the overflow, the post-exploitation impact ranges from application termination and persistent denial of service to the potential execution of arbitrary native instructions within the context of the running process. Because the exploit details have been publicly disclosed, systems running unpatched versions of the component are at immediate risk if local threat actors can interact with the MMS protocol handling routines or inject malicious responses."
}