Executive Summary
In July 2026, MZ Automation's lib60870 library, widely used in industrial control systems, was found to have critical vulnerabilities identified as CVE-2026-61893 and CVE-2026-63033. These flaws, present in version 2.4.0, could be exploited by attackers to crash the parsing process, leading to a denial of service. The vulnerabilities stem from out-of-bounds read errors triggered by specially crafted IEC 60870-5-104 I-frames, allowing unauthorized access to memory beyond allocated buffers. (windowsforum.com)
Given the widespread deployment of lib60870 in critical infrastructure sectors such as energy, water, and manufacturing, these vulnerabilities pose significant operational risks. Organizations are urged to update to version 2.4.1 or later to mitigate potential threats. (windowsforum.com)
Why This Matters Now
The discovery of these vulnerabilities underscores the importance of proactive vulnerability management in industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, timely patching and robust security practices are essential to prevent potential disruptions and ensure operational continuity.
Attack Path Analysis
An adversary exploits a vulnerability in the MZ Automation lib60870 library by sending a crafted IEC 60870-5-104 I-frame, leading to an out-of-bounds read and potential denial-of-service. Upon successful exploitation, the adversary gains unauthorized access to the system. The adversary then escalates privileges to gain higher-level access. Utilizing the elevated privileges, the adversary moves laterally within the network to access other critical systems. The adversary establishes a command and control channel to maintain persistent access and control over the compromised systems. Sensitive data is exfiltrated from the compromised systems to external servers. Finally, the adversary disrupts operations by causing system crashes or other forms of denial-of-service.
Kill Chain Progression
Initial Compromise
Description
An adversary exploits a vulnerability in the MZ Automation lib60870 library by sending a crafted IEC 60870-5-104 I-frame, leading to an out-of-bounds read and potential denial-of-service.
Related CVEs
CVE-2026-61893
CVSS 6.5A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.
Affected Products:
MZ Automation GmbH lib60870 – 2.4.0
Exploit Status:
no public exploitCVE-2026-63033
CVSS 6.5A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer.
Affected Products:
MZ Automation GmbH lib60870 – 2.4.0
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploitation of Remote Services
Exploitation for Evasion
Loss of Control
Manipulation of Control
Brute Force I/O
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Flaw Remediation
Control ID: SI-2
PCI DSS 4.0 – System and Software Security
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Critical vulnerability in IEC 60870-5-104 protocol library affects SCADA systems, enabling out-of-bounds read attacks that could crash energy grid control devices.
Oil/Energy/Solar/Greentech
Buffer overflow vulnerabilities in industrial communication protocols threaten operational technology systems, requiring immediate patching to prevent service disruptions and safety incidents.
Water and Wastewater Systems
Crafted I-frame attacks targeting lib60870 library could destabilize water treatment facility control systems, compromising infrastructure availability and public safety operations.
Chemical
Network-accessible vulnerabilities in industrial control protocols expose chemical manufacturing processes to denial-of-service attacks, requiring enhanced segmentation and monitoring capabilities.
Sources
- MZ Automation lib60870https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11Verified
- Heap-buffer-overflow in TestCommand_getFromBuffer (cs101_information_objects.c:6577)https://github.com/mz-automation/lib60870/security/advisories/GHSA-g3w7-x5rx-83xmVerified
- Heap-buffer-overflow in InformationObject_ParseObjectAddress (cs101_information_objects.c:241)https://github.com/mz-automation/lib60870/security/advisories/GHSA-7v97-jmwv-w5j7Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the adversary's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The adversary's initial access may be constrained, reducing the likelihood of successful exploitation.
Control: Zero Trust Segmentation
Mitigation: The adversary's ability to escalate privileges may be constrained, reducing the scope of unauthorized access.
Control: East-West Traffic Security
Mitigation: The adversary's lateral movement may be constrained, reducing the reach to other critical systems.
Control: Multicloud Visibility & Control
Mitigation: The adversary's ability to establish command and control channels may be constrained, reducing persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The adversary's data exfiltration efforts may be constrained, reducing the volume of data transferred to external servers.
The adversary's ability to disrupt operations may be constrained, reducing the severity of system crashes or denial-of-service.
Impact at a Glance
Affected Business Functions
- SCADA Systems
- Remote Monitoring
- Control Systems
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of control system data and operational parameters.
Recommended Actions
Key Takeaways & Next Steps
- • Implement inline intrusion prevention systems (IPS) to detect and block exploit attempts targeting known vulnerabilities.
- • Apply zero trust segmentation to limit lateral movement within the network.
- • Enhance egress security and policy enforcement to prevent unauthorized data exfiltration.
- • Deploy threat detection and anomaly response mechanisms to identify and respond to suspicious activities.
- • Regularly update and patch systems to mitigate known vulnerabilities.



