Mz-automation libiec61850是Mz-automation个人开发者开源的一个 IEC 61850 协议的开源库。 Mz-automation libIEC61850 1.6.1及之前版本存在输入验证错误漏洞,该漏洞源于L2 GOOSE和R-GOOSE共享解析器中的空指针取消引用,可能允许相邻网络攻击者通过发送包含格式错误TLV值的特制GOOSE帧,导致订阅应用程序崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MZ Automation | libIEC61850 | 1.0.0≤ 1.6.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MZ Automation | libIEC61850 | 1.0.0 ~ 1.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16002 | 8.2 HIGH | Out-of-bounds Read in MZ Automation lib60870 |
| CVE-2026-49035 | 8.1 HIGH | Stack-based Buffer Overflow in MZ Automation libIEC61850 |
| CVE-2026-50039 | 7.5 HIGH | Stack-based Buffer Overflow in MZ Automation libIEC61850 |
| CVE-2026-50032 | 7.5 HIGH | NULL Pointer Dereference in MZ Automation libIEC61850 |
No comments yet