CVE-2026-66720
Received Received - Intake

GOOSE Subscriber Heap Out-of-Bounds Read in IEC 61850

Vulnerability report for CVE-2026-66720, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: ICS-CERT

Description

The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the GOOSE subscriber component failing to properly validate the UTC timestamp in unauthenticated IEC 61850 GOOSE Layer-2 multicast messages. A specially crafted frame with an undersized timestamp can cause a heap out-of-bounds read, leading to a process crash and denial-of-service.

Detection Guidance

Detecting this vulnerability requires monitoring for malformed IEC 61850 GOOSE messages with undersized UTC timestamps. Use network analyzers like Wireshark to capture and inspect Layer-2 multicast traffic on EtherType 0x88B8. Look for GOOSE frames with timestamp fields shorter than expected.

Impact Analysis

This vulnerability can cause your system to crash and become unavailable due to a denial-of-service condition when processing malicious GOOSE messages. It affects systems using IEC 61850 GOOSE protocols, potentially disrupting critical operations.

Compliance Impact

This vulnerability causes a denial-of-service condition by crashing the GOOSE subscriber process, which could disrupt critical infrastructure operations. For GDPR, this may impact availability of systems processing personal data, potentially violating Article 32 requirements for resilience. For HIPAA, it could affect the availability of protected health information systems, risking compliance with Security Rule standards for access and integrity.

Mitigation Strategies

Immediately update the GOOSE subscriber component to the latest patched version. Isolate affected systems from untrusted networks. Implement strict input validation for GOOSE messages. Monitor for crashes or unusual behavior in GOOSE processing subsystems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66720. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart