Infinite loop in libIEC61850 - #VU136970
Published: July 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an infinite loop in parseUserInformation() when parsing a malformed ACSE AARE PDU during MMS / IEC 61850 association handling. A remote attacker can send a specially crafted AARE PDU to cause a denial of service.
The issue is reachable before authentication.