MEDIUMVulnerability

CVE-2026-66720

The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition.

Properties

severity
MEDIUM
score
6.5
epss_score
0.00175
cve_id
CVE-2026-66720
vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
published_at
2026-07-30T23:16:53.830
last_modified
2026-09-03T17:58:18.790
epss_percentile
0.07021

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Out-of-bounds Read

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-66720 — Ninja Signal Threat Intelligence | Ninja Signal