CVE-2026-61893

Summary

A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.

Affected Software

VendorProductVersion RangeStatus
MZ Automationlib608702.4.0affected
MZ Automationlib608702.4.1unaffected

Weaknesses

  • CWE-125: CWE-125

References