Boundary Handling Flaw in MMS BER Decoder Affects Major Vendor's Product
CVE-2026-63550
7.1HIGH
What is CVE-2026-63550?
The MMS BER decoder is susceptible to a boundary-handling flaw during the processing of specific fields in confirmed-request messages. This issue arises when a specially crafted BER-encoded element is transmitted over an established MMS session, utilized through TCP port 102. As a result of the decoding process advancing its internal read position incorrectly, it leads to a heap out-of-bounds read condition. This flaw can cause the MMS handling process to terminate unexpectedly, which may result in a denial-of-service situation, affecting system availability.
Affected Version(s)
libiec61850 0 < 1.6.2
libiec61850 1.6.2
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Arun Babu of Central Power Research Institute reported this vulnerability to CISA.
