# Eight Parser Flaws in a Widely Deployed IEC 61850 Library Put Energy Infrastructure at Risk
## The Threat
MZ Automation GmbH's libiec61850 — an open-source C library that implements the IEC 61850 communication standard for power substation automation — contains eight separate out-of-bounds read vulnerabilities, all patched in version 1.6.2. The flaws span two distinct attack surfaces within the library: the GOOSE protocol subscriber used for real-time substation messaging, and the MMS (Manufacturing Message Specification) BER decoder used for device-to-device session communication.
The GOOSE vulnerabilities are particularly notable because GOOSE (Generic Object Oriented Substation Event) frames travel as unauthenticated Layer-2 multicast packets — there is no handshake, no credential check, and no session to disrupt first. An attacker already on the process bus network can send a single malformed Ethernet frame and crash the subscriber process. The MMS flaws require an established TCP session on port 102 with low-privilege access, which is a slightly higher bar, but still reachable for any attacker who has achieved lateral movement into an operational technology network.
The root cause across all eight CVEs is the same class of bug: boundary handling errors in message parsers that trust length or position fields from the incoming packet without fully validating them. This is exactly what aggressive fuzzing surfaces — and the fact that eight distinct bugs were found in the same library, covering both its major protocol parsers, suggests a systematic audit rather than incidental discovery. Whether that audit came from MZ Automation, a security researcher, or a government disclosure program, the result is a patch that organizations deploying libiec61850 need to apply immediately.
## Severity and Impact
| CVE | CVSS v3.1 Score | CVSS v4.0 Score | Vector (v3.1) | Attack Surface | CWE |
|-----|----------------|----------------|---------------|----------------|-----|
| CVE-2026-66720 | 6.5 MEDIUM | 7.1 HIGH | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | GOOSE subscriber — UTC timestamp field | CWE-125 |
| CVE-2026-66369 | 6.5 MEDIUM | 7.1 HIGH | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | GOOSE parser — off-by-one in buffer position | CWE-125 |
| CVE-2026-63550 | 6.5 MEDIUM | 7.1 HIGH | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H | MMS BER decoder — confirmed-request fields | CWE-125 |
| CVE-2026-65421 | 6.5 MEDIUM | 7.1 HIGH | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H | MMS BER decoder — fixed-width boolean/integer fields | CWE-125 |
| CVE-2026-66364 | 6.5 MEDIUM | 7.1 HIGH | — | MMS/GOOSE parser | CWE-125 |
| CVE-2026-66349 | 6.5 MEDIUM | 7.1 HIGH | — | MMS/GOOSE parser | CWE-125 |
| CVE-2026-56758 | 6.5 MEDIUM | 7.1 HIGH | — | MMS/GOOSE parser | CWE-125 |
| CVE-2026-66360 | 6.5 MEDIUM | 7.1 HIGH | — | MMS/GOOSE parser | CWE-125 |
All vulnerabilities result in heap out-of-bounds reads that terminate the affected process, causing a denial-of-service condition. No confidentiality or integrity impact is claimed; the sole confirmed consequence is availability loss. The vendor-reported aggregate CVSS score is 7.5 HIGH (AV:N).
## Affected Products
Primary deployment context: energy sector substation automation systems, protection relays, Intelligent Electronic Devices (IEDs), and SCADA gateways globally implementing IEC 61850 communication.
## Mitigations
Patch first. MZ Automation GmbH recommends updating to libiec61850 version 1.6.2, which addresses all eight CVEs. Organizations integrating this library into custom IED firmware or gateway software should rebuild and redeploy from the patched source.
If patching is not immediately possible:
## References
---
## HackWire Analysis
Eight CVEs, one library, one version boundary, one patch. That's a clean story — but what it obscures is how many devices in production are running vulnerable libiec61850 today and have no realistic near-term patch path.
IEC 61850 is the backbone protocol for modern power substation automation. It governs how protection relays trip breakers, how bay controllers exchange state, how SCADA systems query field devices. libiec61850 is an open-source implementation that gets embedded in commercial IED firmware, third-party gateway software, and custom integration tools. The library itself can be updated in an afternoon; the firmware stacks that ship it cannot. Vendors have qualification cycles, certification requirements, and change-control processes that make a six-week firmware update an optimistic timeline.
The GOOSE attack surface deserves specific attention. GOOSE was deliberately designed to skip TCP/IP — it runs directly over Ethernet because substation protection cannot tolerate the latency of a routed stack. That design decision, sound for its original purpose, means authentication is absent by design. Any device on the process bus segment can send a crafted GOOSE frame. The advisory notes these bugs require network-adjacent access (AV:A), but that's precisely where compromised engineering workstations, rogue maintenance laptops, and insider-connected devices sit. The process bus is not the internet; it is not hardened against all comers.
The pattern here — multiple parser bugs discovered in a single audit sweep — should prompt defenders to ask whether other IEC 61850 stacks have received the same scrutiny. libiec61850 is open-source and auditable. Proprietary implementations from major IED vendors may carry similar bugs that have never been found because nobody looked hard enough with the right tools. That's the uncomfortable subtext beneath a tidy eight-CVE advisory.
— HackWire Editorial
---
## Related Coverage