Description
The MMS BER decoder contains a boundary-handling flaw in the processing
of certain fields within confirmed-request messages. When a crafted
BER-encoded element is received over an established MMS session (TCP
port 102), the decoder may advance its internal read position
incorrectly, leading to a heap out-of-bounds read. This condition causes
the MMS handling process to terminate unexpectedly, resulting in a
denial-of-service.
of certain fields within confirmed-request messages. When a crafted
BER-encoded element is received over an established MMS session (TCP
port 102), the decoder may advance its internal read position
incorrectly, leading to a heap out-of-bounds read. This condition causes
the MMS handling process to terminate unexpectedly, resulting in a
denial-of-service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
MZ Automation GmbH recommends that users update to version 1.6.2.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 31 Jul 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mz-automation
Mz-automation libiec61850 |
|
| Vendors & Products |
Mz-automation
Mz-automation libiec61850 |
Thu, 30 Jul 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position incorrectly, leading to a heap out-of-bounds read. This condition causes the MMS handling process to terminate unexpectedly, resulting in a denial-of-service. | |
| Title | MZ Automation libiec61850 Out-of-bounds Read | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-07-30T22:43:21.063Z
Reserved: 2026-07-27T19:32:49.393Z
Link: CVE-2026-63550
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-31T00:30:18Z
Weaknesses