CVE-2026-49035
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MZ Automation | libIEC61850 | 1.0.0 <= 1.6.1 | affected |
Weaknesses
- CWE-122: CWE-122 Heap-based buffer overflow
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.