Buffer Overflow Vulnerability in IEC 60870-5-104 Protocol by MZ Automation
CVE-2026-63033

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-63033?

A vulnerability exists in the IEC 60870-5-104 protocol implemented by MZ Automation, where an attacker can craft a malicious I-frame containing an object count greater than the capacity of the Application Service Data Unit (ASDU). When this malformed data is processed, it leads to a buffer overflow, allowing the InformationObject_ParseObjectAddress function to read beyond the intended memory limit, potentially compromising the application's stability and security.

Affected Version(s)

lib60870 2.4.0

lib60870 2.4.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arun babu puthuparambil of Central Power Research Institute, Bengaluru, India reported this vulnerability to CISA.
.