CVE-2026-61893

Severity CVSS v4.0:
MEDIUM
Type:
CWE-125 Out-of-bounds Read
Publication date:
30/07/2026
Last modified:
31/07/2026

Description

A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an <br /> inflated object count causes TestCommand_getFromBuffer to read one byte <br /> past the end of the heap-allocated message buffer.