CVE-2026-61893
EUVD-2026-5136230.07.2026, 23:16
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mz-automation | lib60870 | 2.4.0 | CNA |
Common Weakness Enumeration
References