Inside Vidar’s ABE Bypass: From Memory Scanning to APC Injections
June 18, 2026 · CISA (US-CERT) · Severity: MEDIUM
View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions. The following versions of MZ Automation libIEC61850 are affected: libIEC61850 >=v1.0.0|<=v1.6.1 CVSS Vendor Equipment Vulnerabilities v3 8.1 MZ Automation MZ Automation libIEC61850 Stack-based Buffer Overflow, Heap-based Buffer Overflow, Improper Handling of Syntactically Invalid Structure, NULL Pointer Dereference Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-50039 The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a ReadRequest. View CVE Details Affected Products MZ Automation libIEC61850 Vendor:MZ Automation Product Version:MZ Automation libIEC61850: >=v1.0.0|<=v1.6.1 Product Status:known_affected Remediations Vendor fixMZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850.https://github.com/mz-automation/libiec61850 Relevant CWE: CWE-121 Stack-based Buffer Overflow Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-49035 The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled. View CVE Details Affected Products MZ Automation...
Key Takeaways
- A Technical Walkthrough of How Vidar Defeats Application-Bound Encryption.