MZ Automation lib60870

Summary

CISA has alerted that successful exploitation of vulnerabilities in MZ Automation lib60870 could crash the device being accessed. Specifically, CVE-2026-61893 and CVE-2026-63033 affect lib60870 version 2.4.0, allowing an out-of-bounds read that leads to a crash.

IFF Assessment

FOE

These vulnerabilities enable attackers to crash critical infrastructure devices, posing a significant risk to operational stability.

Severity

6.5 Medium

The CVSS score of 6.5 (MEDIUM) is based on a network attack vector, low complexity, no privileges required, no user interaction, and the impact of the vulnerability causing the device to crash.

Defender Context

Defenders in critical infrastructure sectors such as Energy, Water and Wastewater, and Critical Manufacturing should be aware of these vulnerabilities. The affected lib60870 library is widely deployed globally. Prompt patching or mitigation is crucial to prevent denial-of-service attacks.

Read Full Story →