CVE-2026-18583

medium

Description

A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping.c of the component MMS Request Handler. This manipulation causes out-of-bounds read. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 1.6.2 is capable of addressing this issue. Patch name: 062062daf4cb50c7aa76e01d6fb4d58fc9278a7d. Upgrading the affected component is recommended. The vendor was contacted early about this disclosure.

References

https://vuldb.com/vuln/385412/cti

https://vuldb.com/vuln/385412

https://vuldb.com/submit/844921

https://vuldb.com/cve/CVE-2026-18583

https://github.com/mz-automation/libiec61850/security/advisories/GHSA-7v2x-39mw-2979

https://github.com/mz-automation/libiec61850/releases/tag/v1.6.2

https://github.com/mz-automation/libiec61850/commit/062062daf4cb50c7aa76e01d6fb4d58fc9278a7d

https://github.com/mz-automation/libiec61850/

https://github.com/gff-cw/information/issues/3

Details

Source: Mitre, NVD

Published: 2026-08-03

Updated: 2026-08-03

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Severity: Medium

CVSS v4

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Severity: Medium