


Perceptive Security
SOC/SIEM Consultancy

A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validat…
Published:
5 augustus 2026 om 22:00:00
Alert date:
6 augustus 2026 om 14:02:41
Source:
nvd.nist.gov
Critical Infrastructure, Network Infrastructure
A heap-based buffer overflow vulnerability exists in lib60870-C version 2.4.0, specifically in the server-side FileSegment ASDU encoding path. The vulnerability is triggered because FileSegment_encode() only validates the standalone segment length using FileSegment_GetMaxDataSize() but fails to verify the residual capacity of the current ASDU frame prior to encoding object fields and segment data. This flaw can result in heap memory corruption during IEC 60870-5 protocol communication. lib60870-C is an open-source implementation of the IEC 60870-5-101/104 protocol commonly used in industrial control and critical infrastructure environments. An attacker exploiting this vulnerability could potentially cause a denial of service or achieve remote code execution on affected systems. The issue is tracked under CVE-2026-67873 and was disclosed via the NVD and the project's GitHub repository.
Technical details
Mitigation steps:
Affected products:
lib60870-C 2.4.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67873
https://github.com/mz-automation/lib60870
https://github.com/mz-automation/lib60870/blob/master/user_guide.adoc
https://github.com/mz-automation/lib60870/issues/201
https://github.com/mz-automation/lib60870/releases/tag/v2.4.0
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
