MZ Automation maintains a focused portfolio of industrial protocol libraries—particularly libiec61850 and lib60870—that are embedded in power systems, energy infrastructure, and critical industrial control applications. Despite a narrow product scope, these libraries occupy a prominent position in the vulnerability landscape due to their deep integration into mission-critical operational technology environments where reliability and supply-chain dependencies drive risk. The vendor's disclosure history reflects the specialized, protocol-oriented nature of these components, and defenders should prioritize tracking updates to these libraries as part of inventory and supply-chain assurance for industrial and energy sectors. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mz Automation over time
Signals from CVEs in this vendor scope (44 CVEs).
44 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18957CRITICAL An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c. | Nov 5, 2018 | 9.8 | 49 | NO | YES |
CVE-2026-49035HIGH The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memo | Jul 23, 2026 | 8.1 | 36 | NO | NO |
CVE-2026-16002HIGH The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service. | Jul 23, 2026 | 8.2 | 35 | NO | NO |
CVE-2026-50032HIGH A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty lis | Jul 23, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-50039HIGH The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a Read Request. | Jul 23, 2026 | 7.5 | 34 | NO | NO |
CVE-2022-2970CRITICAL MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) does not sanitize input before memcpy is used, which coul | Sep 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-18834CRITICAL An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c. | Oct 30, 2018 | 9.8 | 31 | NO | NO |
CVE-2026-50103MEDIUM A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE fram | Jul 23, 2026 | 6.5 | 30 | NO | NO |
CVE-2022-2972CRITICAL MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) is vulnerable to a stack-based buffer overflow, which cou | Sep 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-15158CRITICAL In libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer underflow will happen leading to heap buffer overflow. This | Aug 26, 2020 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (44 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mz Automation.
Media articles that mention a CVE ID that affects a product developed by Mz Automation — matched by CVE ID, not by vendor name.