CVE-2026-63033
Received Received - Intake

IEC 60870-5-104 Buffer Overflow in I-frame Parsing

Vulnerability report for CVE-2026-63033, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: ICS-CERT

Description

A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a crafted IEC 60870-5-104 I-frame that declares an object count exceeding the space available in the ASDU body. This causes a function to read one byte past the end of a heap-allocated message buffer, potentially leading to memory corruption or crashes.

Detection Guidance

This vulnerability involves a crafted IEC 60870-5-104 I-frame with an object count exceeding buffer limits. Detection requires monitoring network traffic for malformed IEC 60870-5-104 packets or unusual object counts in ASDU bodies. Use protocol analyzers like Wireshark with IEC 60870-5-104 dissectors to inspect traffic for invalid frames.

Impact Analysis

The vulnerability could allow an attacker to cause denial-of-service conditions or execute arbitrary code on systems processing IEC 60870-5-104 traffic. This may disrupt critical infrastructure operations relying on this protocol.

Compliance Impact

This vulnerability involves a buffer overflow in IEC 60870-5-104 I-frame parsing, which could lead to memory corruption or crashes. While not directly tied to GDPR or HIPAA, such vulnerabilities may impact compliance by exposing systems to unauthorized access or data integrity issues if exploited.

Mitigation Strategies

Update or patch the affected IEC 60870-5-104 protocol implementation to handle malformed I-frames correctly. Monitor network traffic for unusual IEC 60870-5-104 frames with excessive object counts. Disable or restrict network access to systems using this protocol if patches are unavailable.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63033. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart