Cyber Resilience
← All news
Confirmed

MZ Automation libIEC61850

CISA flags flaws in MZ Automation libIEC61850 (v1.0.0–1.6.1) and lib60870 (≤2.4.0). An unauthenticated network-adjacent attacker can crash IEC 61850 services or run code; lib60870 has a DoS via OOB read. Patch if these libraries sit in your OT stack.
Sources (2)
What this means for you — CISO:If your OT estate uses MZ Automation libIEC61850 (≤1.6.1) or lib60870 (≤2.4.0) for IEC 61850/60870, treat these as network-adjacent crash and code-execution risks on protection and control paths—inventory usage and apply vendor fixes on the OT change window.
What this means for you — Lean IT orgs:These libraries sit in utility and industrial control stacks. Most lean-IT shops do not run them and can ignore this unless a vendor or partner you depend on operates substation or SCADA gear—ask them if they use MZ Automation and whether they have patched.
What this means for you — MSP:Scan client OT and energy accounts for libIEC61850 and lib60870; prioritize anyone with substation, protection, or telecontrol systems and push the fixed versions before the next maintenance window.
What this means for you — Researcher:CISA ICSA-26-204-06 and ICSA-26-204-07 cover unauthenticated network-adjacent crash/RCE in libIEC61850 (≤1.6.1) and an OOB-read DoS in lib60870 (≤2.4.0, CVSS 8.2)—worth diffing the CSAF for root cause and exploitability on IEC stacks.