BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

News Vulnerability
VulnerabilityCISA·5d ago

MZ Automation lib60870

p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-07.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. /strong /p p The following versions of MZ Automation lib60870 are affected: /p ul li lib60870 lt;=2.4.0 /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 8.2 /td td MZ Automation /td td MZ Automation lib60870 /td td Out-of-bounds Read /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Chemical, Energy, Water and Wastewater /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-16002 /a /h3 div class= csaf-accordion-content p The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-16002 View CVE Details /a /p hr h4 Affected Products /h4 h5 MZ Automation lib60870 /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br MZ Automation /div div class= ics-version strong Product Version: /strong br MZ Automation lib60870: lt;=2.4.0 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Vendor fix /strong br MZ automation recommends users update to version 2.4.1 or later. Documentation can be found at https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv. br a href= https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv /a /p /div p strong Relevant CWE: /strong a href= https://cwe.mitre.org/data/definitions/125.html CWE-125 Out-of-bounds Read /a /p hr h4 Metrics /h4 div class= csaf-table csaf-metrics-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS Version /th th role= columnheader Base Score /th th role= columnheader Base Severity /th th role= columnheader Vector String /th /tr /thead tbody tr td 3.1 /td td 8.2 /td td HIGH /td td a href= https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H /a /td /tr tr td 4.0 /td

Sign in to read the full article

Create a free account to access all news, downloads, and community features

Originally published by CISA

Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-07

This article is shared for informational purposes. All rights belong to the original author and publisher. If you are the copyright holder and would like this content removed, please contact us.

Shared on IT-Hub by admin