Heap Out-of-Bounds Read in MMS Server Connection Handler by Leading Vendor
CVE-2026-66349
6.9MEDIUM
What is CVE-2026-66349?
The MMS server's connection handler contains a critical flaw in how it processes BER-encoded request data. When an MMS confirmed request PDU with an extended BER tag is received over an established session, the decoder fails to perform proper bounds checking. This oversight can lead to a one byte heap out-of-bounds read, ultimately causing the MMS service process to crash. The result of this vulnerability is a denial-of-service condition, leaving systems reliant on the MMS server vulnerable until the issue is addressed.
Affected Version(s)
libiec61850 0 < 1.6.2
libiec61850 1.6.2
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Arun Babu of Central Power Research Institute reported this vulnerability to CISA.
