Multiple High‑Severity DoS Vulnerabilities in MZ Automation libiec61850 Library Threaten Energy Control Systems
What It Is — The open‑source libiec61850 library (versions < 1.6.2) contains eight CVEs that let an unauthenticated attacker send a malformed IEC 61850 GOOSE frame, causing an out‑of‑bounds heap read and crashing the process.
Exploitability — CVSS v3 7.5 (High); the flaw is trivial to trigger on any device that parses GOOSE traffic. No public PoC is required, making exploitation realistic for nation‑state or opportunistic actors.
Affected Products — MZ Automation GmbH libiec61850 < 1.6.2, embedded in substation automation equipment deployed worldwide across the energy sector.
Why It Matters for Compliance & Audit Readiness
- SOC 2 Availability (CC6.1) obligates organizations to demonstrate that critical control‑system software is kept up‑to‑date; a DoS‑capable library directly violates that control.
- Continuous control‑monitoring platforms must capture library version and patch status to provide immutable audit evidence of timely remediation.
- Energy‑sector buyers now request proof of a formal vulnerability‑management process as part of their SOC 2 assessments, turning patch cadence into a deal‑breaker.
Recommended Actions
- Upgrade libiec61850 to version 1.6.2 or later on every affected device.
- Conduct an inventory of all IEC 61850‑enabled assets and map the library version to the SOC 2 Availability control matrix.
- Deploy automated version‑tracking and patch‑validation tooling that logs remediation actions for audit review.
Source: CISA Advisory – ICSA‑26‑211‑10