C
月内に
MZ Automation GmbHのlibiec61850ライブラリに、サービス拒否(DoS)を引き起こす複数の脆弱性
📌 一言でいうと
MZ Automation GmbHのlibiec61850ライブラリに、サービス拒否(DoS)を引き起こす複数の脆弱性が発見されました。特にCVE-2026-66720では、不正に細工されたGOOSEメッセージを処理する際にヒープ境界外読み取りが発生し、プロセスがクラッシュします。影響を受けるバージョンは1.6.2未満であり、エネルギーセクターなどの重要インフラで利用されている可能性があります。
🔍該当判定
- MZ Automation GmbH社のライブラリ『libiec61850』を自社製品やシステムに組み込んで利用している
- 電力インフラなどの産業制御システム(ICS)で、IEC 61850規格の通信を利用している
- 利用している『libiec61850』のバージョンが 1.6.2 未満である
上記いずれにも該当しない → 静観でOK
✅該当時の対応
影響を受けるlibiec61850ライブラリをバージョン1.6.2以降にアップデートすることを推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】MZ Automation GmbH libiec61850 脆弱性対応について
お疲れさまです。libiec61850に関する脆弱性情報共有です。
■ 概要
MZ Automation GmbHのlibiec61850において、DoS状態を誘発する複数の脆弱性が報告されました。CVSS v3スコアは7.5(High)であり、不正なGOOSEフレームの処理によるヒープ境界外読み取りなどが原因でプロセスがクラッシュします。
■ 影響範囲
- 対象製品: MZ Automation GmbH libiec61850
- 対象バージョン: 1.6.2 未満
■ 対応手順
1. 利用しているライブラリのバージョンを確認してください。
2. 脆弱性が修正されたバージョン 1.6.2 以降へアップデートを適用してください。
■ 参考情報
- CISA ICS Advisory ICSA-26-211-10
対応優先度: 高
対応期限: 速やかに
お疲れさまです。libiec61850に関する脆弱性情報共有です。
■ 概要
MZ Automation GmbHのlibiec61850において、DoS状態を誘発する複数の脆弱性が報告されました。CVSS v3スコアは7.5(High)であり、不正なGOOSEフレームの処理によるヒープ境界外読み取りなどが原因でプロセスがクラッシュします。
■ 影響範囲
- 対象製品: MZ Automation GmbH libiec61850
- 対象バージョン: 1.6.2 未満
■ 対応手順
1. 利用しているライブラリのバージョンを確認してください。
2. 脆弱性が修正されたバージョン 1.6.2 以降へアップデートを適用してください。
■ 参考情報
- CISA ICS Advisory ICSA-26-211-10
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] MZ Automation GmbH libiec61850 Vulnerabilities
Dear Team,
We are sharing technical information regarding vulnerabilities found in the libiec61850 library by MZ Automation GmbH.
■ Overview
Multiple vulnerabilities have been identified that could allow an attacker to cause a Denial-of-Service (DoS) condition. With a CVSS v3 score of 7.5, these flaws (including CVE-2026-66720) involve heap out-of-bounds reads triggered by specially crafted GOOSE frames, leading to process crashes.
■ Scope
- Product: MZ Automation GmbH libiec61850
- Affected Versions: < 1.6.2
■ Mitigation Steps
1. Verify the current version of the libiec61850 library in use.
2. Update the library to version 1.6.2 or later to resolve these vulnerabilities.
■ Reference
- CISA ICS Advisory ICSA-26-211-10
Priority: High
Deadline: Immediate
Dear Team,
We are sharing technical information regarding vulnerabilities found in the libiec61850 library by MZ Automation GmbH.
■ Overview
Multiple vulnerabilities have been identified that could allow an attacker to cause a Denial-of-Service (DoS) condition. With a CVSS v3 score of 7.5, these flaws (including CVE-2026-66720) involve heap out-of-bounds reads triggered by specially crafted GOOSE frames, leading to process crashes.
■ Scope
- Product: MZ Automation GmbH libiec61850
- Affected Versions: < 1.6.2
■ Mitigation Steps
1. Verify the current version of the libiec61850 library in use.
2. Update the library to version 1.6.2 or later to resolve these vulnerabilities.
■ Reference
- CISA ICS Advisory ICSA-26-211-10
Priority: High
Deadline: Immediate