← Back to feed
Vulnerabilities & PatchesEmerging1 sourceJul 30, 2026 · 12:00via CISA Alerts

MZ Automation lib60870

Brief

View CSAF

Summary

Successful exploitation of these vulnerabilities could crash the device being accessed. The following versions of MZ Automation lib60870 are affected: lib60870 2.

  • 0 (CVE-2026-61893, CVE-2026-63033) CVSS Vendor Equipment Vulnerabilities

v3 6.5 MZ Automation GmbH MZ Automation lib60870 Out-of-bounds Read

Background

Critical Infrastructure Sectors: Energy, Water and Wastewater, Critical Manufacturing, Chemical Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-61893 A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.

View CVE Details Affected Products MZ Automation lib60870 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH lib60870: 2. 4.

Read more on CISA Alerts