Out-of-bounds read in libIEC61850 - #VU136971
Published: July 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in parseUserInformation() when parsing a malformed ACSE AARE PDU during MMS / IEC 61850 association handling. A remote attacker can send a specially crafted AARE PDU to disclose sensitive information.
The out-of-bounds read is a 1-byte heap read and is reachable before authentication.