IM
IronMonkey Threat Research
‹ Back to ICS Advisories

MZ Automation lib60870

MEDIUM
CVSS 6.5
Date 2026-07-30T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could crash the device being accessed.

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2026-63033 6.5 medium
A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer.
CVE-2026-61893 6.5 medium
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.

// Remediations (2)

Mitigation: MZ Automation recommends users update to version 2.4.1 when available.
MZ Automation recommends users update to version 2.4.1 when available.
Patch: See MZ Automation advisory for more information: https://github.com/mz-automation/lib60870/security/
See MZ Automation advisory for more information: https://github.com/mz-automation/lib60870/security/advisories/GHSA-7v97-jmwv-w5j7

// References