MZ Automation libIEC61850

Summary

CISA has alerted about vulnerabilities in MZ Automation libIEC61850, versions 1.0.0 through 1.6.1. Successful exploitation could allow an unauthenticated, network-adjacent attacker to crash services or execute arbitrary code, impacting critical infrastructure like manufacturing, energy, and transportation. The vulnerabilities include stack-based buffer overflows, heap-based buffer overflows, and improper handling of invalid structures.

IFF Assessment

FOE

These vulnerabilities allow attackers to disrupt critical infrastructure services and execute arbitrary code, posing a significant threat to defenders.

Severity

7.5 High

The CVSS v3.1 score of 7.5 (HIGH) is based on the ability for an unauthenticated attacker to impact critical functions remotely via network access, leading to potential denial-of-service or arbitrary code execution.

Defender Context

This alert highlights critical vulnerabilities in OT systems that are essential for critical infrastructure. Defenders must prioritize patching or mitigating these issues to prevent widespread disruption. It underscores the importance of network segmentation and access controls for OT environments.

Read Full Story →