Buffer Overflow Vulnerability in IEC 60870-5-104 Protocol by MZ Automation
CVE-2026-63033
6.9MEDIUM
What is CVE-2026-63033?
A vulnerability exists in the IEC 60870-5-104 protocol implemented by MZ Automation, where an attacker can craft a malicious I-frame containing an object count greater than the capacity of the Application Service Data Unit (ASDU). When this malformed data is processed, it leads to a buffer overflow, allowing the InformationObject_ParseObjectAddress function to read beyond the intended memory limit, potentially compromising the application's stability and security.
Affected Version(s)
lib60870 2.4.0
lib60870 2.4.1
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
arun babu puthuparambil of Central Power Research Institute, Bengaluru, India reported this vulnerability to CISA.
