CVE-2026-63033

Severity CVSS v4.0:
MEDIUM
Type:
CWE-125 Out-of-bounds Read
Publication date:
30/07/2026
Last modified:
31/07/2026

Description

A crafted IEC 60870-5-104 I-frame with a declared object count exceeding<br /> what fits in the ASDU body causes InformationObject_ParseObjectAddress <br /> to read one byte past the end of the heap-allocated message buffer.