Back to CVE List

CVE-2026-66364

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.5 / 10
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Description

The GOOSE payload parser contains a boundary handling flaw that can be
triggered by a single unauthenticated Layer 2 multicast frame on the
process bus. When processing specific payload fields, an attacker
controlled inner element length may exceed its enclosing length, causing
the parser to over read by one byte. This out-of-bounds read reliably
terminates the subscriber process, resulting in a denial-of-service
condition.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-125
Source
NVD
Vendor
MZ Automation GmbH
Product
libiec61850

External References

Discussion (0)

Add Comment

No comments yet. Be the first!