Multiple Critical Vulnerabilities in MZ Automation libIEC61850
Multiple vulnerabilities have been discovered in the MZ Automation libIEC61850 library, widely used in industrial control systems. These flaws could allow remote attackers to crash systems or potentially execute unauthorized code, disrupting critical energy and manufacturing services.

English Brief
Multiple vulnerabilities have been discovered in the MZ Automation libIEC61850 library, widely used in industrial control systems. These flaws could allow remote attackers to crash systems or potentially execute unauthorized code, disrupting critical energy and manufacturing services.
الموجز العربي
ثغرات أمنية حرجة متعددة في مكتبة MZ Automation libIEC61850
تم اكتشاف ثغرات أمنية متعددة في مكتبة MZ Automation libIEC61850 المستخدمة على نطاق واسع في أنظمة التحكم الصناعية. قد تسمح هذه العيوب للمهاجمين عن بُعد بإيقاف الأنظمة عن العمل أو تنفيذ تعليمات برمجية غير مصرح بها، مما قد يؤدي إلى تعطيل خدمات الطاقة والتصنيع الحيوية.
- 1Inventory assets using libIEC61850 (v1.0.0 - v1.6.1)
- 2Visit https://github.com/mz-automation/libiec61850 to obtain the latest build
- 3Apply the update to affected ICS applications
English Advisory
// Intelligence Summary
Multiple vulnerabilities affecting MZ Automation libIEC61850 versions v1.0.0 through v1.6.1 have been identified. These flaws include heap-based buffer overflows, stack-based buffer overflows, and NULL pointer dereference issues. These vulnerabilities permit unauthenticated network-adjacent attackers to achieve denial-of-service or remote code execution, depending on the environment configuration.
التقرير العربي
// ملخص استخباراتي
تم تحديد ثغرات أمنية متعددة تؤثر على مكتبة MZ Automation libIEC61850 من الإصدار v1.0.0 حتى v1.6.1. تتضمن هذه العيوب تجاوز سعة المخزن المؤقت (Buffer Overflow) في المكدس والكومة، بالإضافة إلى مشاكل إلغاء مرجع المؤشر الفارغ (NULL pointer dereference). تسمح هذه الثغرات للمهاجمين غير المصادق عليهم والمتواجدين ضمن النطاق الشبكي بإيقاف الخدمة أو تنفيذ تعليمات برمجية عن بُعد، اعتماداً على إعدادات البيئة.
// Technical Context
The vulnerabilities include CVE-2026-50039 (Stack-based buffer overflow), CVE-2026-49035 (Heap-based buffer overflow allowing RCE if ASLR is disabled), CVE-2026-50103 (NULL pointer dereference in GOOSE parser), and CVE-2026-50032 (NULL pointer dereference in MMS handler). These flaws arise from improper input validation and memory management within the library's protocol implementation.
// السياق الفني
تشمل الثغرات CVE-2026-50039 (تجاوز سعة المخزن المؤقت في المكدس)، وCVE-2026-49035 (تجاوز سعة المخزن المؤقت في الكومة مما يسمح بتنفيذ تعليمات برمجية إذا تم تعطيل ASLR)، وCVE-2026-50103 (إلغاء مرجع المؤشر الفارغ في محلل GOOSE)، وCVE-2026-50032 (إلغاء مرجع المؤشر الفارغ في معالج MMS). تنبع هذه العيوب من سوء التحقق من المدخلات وإدارة الذاكرة داخل تنفيذ البروتوكول في المكتبة.
// Exposure Notes
The library is deployed globally across critical infrastructure sectors, including energy, manufacturing, and transportation. Systems utilizing the library directly or as a component in third-party products are at risk if exposed to untrusted network traffic.
// ملاحظات التعرض
يتم استخدام المكتبة عالمياً في قطاعات البنية التحتية الحيوية، بما في ذلك الطاقة والتصنيع والنقل. الأنظمة التي تستخدم المكتبة بشكل مباشر أو كمكون في منتجات الطرف الثالث معرضة للخطر إذا كانت مكشوفة لحركة مرور الشبكة غير الموثوقة.
// Defensive Priority
Organizations should immediately update to the latest available build of the libIEC61850 library provided by MZ Automation. Concurrently, minimize network exposure by isolating ICS components behind firewalls and ensuring they are unreachable from the public internet.
// أولوية الدفاع
يجب على المؤسسات التحديث فوراً إلى أحدث إصدار متاح من مكتبة libIEC61850 المقدم من MZ Automation. في الوقت نفسه، يجب تقليل التعرض للشبكة عن طريق عزل مكونات أنظمة التحكم الصناعية (ICS) خلف جدران الحماية وضمان عدم إمكانية الوصول إليها من شبكة الإنترنت العامة.
Mitigation Checklist
- 1Inventory assets using libIEC61850 (v1.0.0 - v1.6.1)
- 2Visit https://github.com/mz-automation/libiec61850 to obtain the latest build
- 3Apply the update to affected ICS applications
- 4Restrict network access: Block external access to ports used by IEC 61850 services
- 5Place control systems behind robust firewalls/VPNs
- 6Monitor logs for abnormal traffic patterns targeting MMS or GOOSE protocol packets
قائمة إجراءات التخفيف
- 1جرد الأصول التي تستخدم مكتبة libIEC61850 (الإصدارات من v1.0.0 إلى v1.6.1)
- 2قم بزيارة الرابط https://github.com/mz-automation/libiec61850 للحصول على أحدث إصدار
- 3تطبيق التحديث على تطبيقات أنظمة التحكم الصناعية المتأثرة
- 4تقييد الوصول إلى الشبكة: حظر الوصول الخارجي إلى المنافذ المستخدمة من قبل خدمات IEC 61850
- 5وضع أنظمة التحكم خلف جدران حماية قوية أو شبكات افتراضية خاصة (VPN)
- 6مراقبة السجلات بحثاً عن أنماط حركة مرور غير طبيعية تستهدف حزم بروتوكول MMS أو GOOSE
- Source: CISA Alerts
# 1. Inventory assets using libIEC61850 (v1.0.0 - v1.6.1)
# 2. Visit https://github.com/mz-automation/libiec61850 to obtain the latest build
# 3. Apply the update to affected ICS applications
# 4. Restrict network access: Block external access to ports used by IEC 61850 services
# 5. Place control systems behind robust firewalls/VPNs
# 6. Monitor logs for abnormal traffic patterns targeting MMS or GOOSE protocol packets