CVE-2026-66360

EUVD-2026-51338
The ISO Presentation layer contains a flaw in the handling of specific 
parameters during normal mode negotiation. A missing length check in the
 processing of the encoded presentation data allows an attacker 
controlled field with a zero length value to trigger a bounded heap over
 read. This condition occurs before MMS session establishment, a crafted
 TCP/102 connection attempt can trigger the issue. The resulting over 
read causes the process to terminate, leading to a denial of service 
condition.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
icscertCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
mz-automationlibiec61850
𝑥
< 1.6.2
CNA