CVE-2026-56758
6.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MZ Automation GmbH | libiec61850 | 0 < 1.6.2 | affected |
| MZ Automation GmbH | libiec61850 | 1.6.2 | unaffected |
Weaknesses
- CWE-125: CWE-125
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-10.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.