CVE-2026-63550
Received Received - Intake

MMS BER Decoder Heap Out-of-Bounds Read

Vulnerability report for CVE-2026-63550, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: ICS-CERT

Description

The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position incorrectly, leading to a heap out-of-bounds read. This condition causes the MMS handling process to terminate unexpectedly, resulting in a denial-of-service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a heap out-of-bounds read flaw in the MMS BER decoder. It occurs when processing certain fields in confirmed-request messages over an MMS session on TCP port 102. A crafted BER-encoded element causes the decoder to advance its internal read position incorrectly, leading to a crash and denial-of-service.

Detection Guidance

Detecting this vulnerability requires monitoring for unexpected termination of MMS handling processes on TCP port 102. Check system logs for crashes in MMS-related services and inspect network traffic for malformed BER-encoded elements. Use tcpdump or Wireshark to capture traffic on port 102 and analyze for anomalies.

Impact Analysis

The vulnerability can cause the MMS handling process to crash unexpectedly, disrupting services that rely on MMS communication. This may lead to service unavailability or downtime for systems using affected MMS implementations.

Compliance Impact

This vulnerability causes a denial-of-service by crashing the MMS handling process, which could disrupt critical communication systems. For compliance with standards like GDPR or HIPAA, such disruptions may impact data availability and integrity requirements, potentially leading to non-compliance if systems fail to maintain expected operational states.

Mitigation Strategies

Immediately restrict access to TCP port 102 to trusted sources only. Update or patch the MMS BER decoder component to fix the boundary-handling flaw. Monitor MMS handling processes for unexpected terminations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63550. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart