Back to CVE List

CVE-2026-66360

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Description

The ISO Presentation layer contains a flaw in the handling of specific
parameters during normal mode negotiation. A missing length check in the
processing of the encoded presentation data allows an attacker
controlled field with a zero length value to trigger a bounded heap over
read. This condition occurs before MMS session establishment, a crafted
TCP/102 connection attempt can trigger the issue. The resulting over
read causes the process to terminate, leading to a denial of service
condition.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-125
Source
NVD
Vendor
MZ Automation GmbH
Product
libiec61850

External References

Discussion (0)

Add Comment

No comments yet. Be the first!