CVE-2026-66720

Summary

The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition.

Affected Software

VendorProductVersion RangeStatus
MZ Automation GmbHlibiec618500 < 1.6.2affected
MZ Automation GmbHlibiec618501.6.2unaffected

Weaknesses

  • CWE-125: CWE-125

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References