No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file src/iec61850/server/mms_mapping/reporting.c of the component URCB Revalidation. The manipulation results in use after free. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 1.6.2 is sufficient to fix this issue. The patch is identified as 486fd57f3aed65bb9d636ff00f9ddce2e450b168. Upgrading the affected component is advised. | |
| Title | MZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after free | |
| First Time appeared |
Mz Automation
Mz Automation libiec61850 |
|
| Weaknesses | CWE-119 CWE-416 |
|
| CPEs | cpe:2.3:a:mz_automation:libiec61850:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mz Automation
Mz Automation libiec61850 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-06T20:30:14.200Z
Reserved: 2026-08-06T13:58:41.401Z
Link: CVE-2026-19108
No data.
No data.
No data.
OpenCVE Enrichment
No data.