CVE-2026-66349

EUVD-2026-51340
The MMS server connection handler contains a flaw in its processing of 
BER-encoded request data. When an MMS confirmed request PDU containing 
an extended BER tag is received over an established session, the decoder
 may advance its internal buffer incorrectly due to a missing bounds 
check. This results in a one byte heap out-of-bounds read and causes the
 MMS service process to terminate, leading to a denial-of-service 
condition.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
icscertCNA
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
mz-automationlibiec61850
𝑥
< 1.6.2
CNA