GOOSE 解析器存在一个“差一”边界处理漏洞,该漏洞可通过进程总线上发送的单个未经身份验证的 Layer-2 组播帧触发。当处理特定 GOOSE 消息字段时,解析器错误地推进其内部缓冲区位置,从而导致堆越界读取。在受影响的平台上,此条件可可靠地终止订阅者进程,并导致拒绝服务(DoS)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MZ Automation GmbH | libiec61850 | < 1.6.2 |
affected |
1.6.2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MZ Automation GmbH | libiec61850 | 0 ~ 1.6.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66360 | 7.5 HIGH | MZ Automation libiec61850 Out-of-bounds Read |
| CVE-2026-66349 | 6.5 MEDIUM | MZ Automation libiec61850 Out-of-bounds Read |
| CVE-2026-66364 | 6.5 MEDIUM | MZ Automation libiec61850 Out-of-bounds Read |
| CVE-2026-65421 | 6.5 MEDIUM | MZ Automation libiec61850 Out-of-bounds Read |
| CVE-2026-56758 | 6.5 MEDIUM | MZ Automation libiec61850 Out-of-bounds Read |
| CVE-2026-66720 | 6.5 MEDIUM | MZ Automation libiec61850 Out-of-bounds Read |
| CVE-2026-63550 | 6.5 MEDIUM | MZ Automation libiec61850 Out-of-bounds Read |
No comments yet