CVE-2026-66360
Received Received - Intake

Heap Overflow in ISO Presentation Layer via TCP/102

Vulnerability report for CVE-2026-66360, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: ICS-CERT

Description

The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap over read. This condition occurs before MMS session establishment, a crafted TCP/102 connection attempt can trigger the issue. The resulting over read causes the process to terminate, leading to a denial of service condition.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial of service issue in the ISO Presentation layer. It occurs due to a missing length check when processing encoded presentation data during normal mode negotiation. An attacker can send a crafted TCP/102 connection attempt with a zero-length field, causing a bounded heap over-read before session establishment. This leads to process termination.

Detection Guidance

Detecting this vulnerability requires monitoring for abnormal termination of processes handling TCP/102 connections. Check system logs for crashes or restarts of services using ISO Presentation layer protocols. Use network monitoring tools to inspect TCP/102 traffic for malformed packets or unexpected disconnections.

Impact Analysis

This vulnerability can cause a denial of service by crashing the affected process. If exploited, it may disrupt services relying on the ISO Presentation layer, particularly those using TCP/102 connections. The impact depends on system exposure and whether the service is critical.

Compliance Impact

This vulnerability causes a denial of service by terminating the process due to a heap over-read, which could disrupt critical operations. For GDPR, this may impact availability of services handling personal data, potentially violating Article 32 requirements for resilience. For HIPAA, it could affect the availability of systems processing protected health information, risking compliance with the Security Rule's integrity and availability standards.

Mitigation Strategies

Immediately restrict or block TCP/102 traffic at the network perimeter. Update or patch affected systems if a fix is available. Monitor for exploitation attempts and isolate any systems showing signs of compromise. Review and restrict access to TCP/102 to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66360. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart