Beveiligingsadvies

CVE-2026-66720

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-30 22:46:52
Laatst bijgewerkt 2026-07-31 15:58:46
Toegewezen door icscert
CVSS-score 7.1
Status PUBLISHED

Beschrijving

The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition.