CVE-2026-63033: Mz Automation LIB60870
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer.
Affected products
- Mz Automation LIB60870: version 2.4.0 only
Published 2026-07-30. Last modified 2026-09-08.