What is CVE-2026-63550?
CVE-2026-63550 is a boundary-handling flaw in the MMS BER decoder affecting the processing of certain fields within confirmed-request messages. When a crafted BER element is received over an established MMS session on TCP port 102, the decoder may incorrectly advance its internal read position, potentially leading to remote code execution or denial of service. Affected SCADA/ICS devices using the MMS protocol should be patched immediately.
Azərbaycanca: CVE-2026-63550 MMS BER dekoderində sərhəd yoxlaması zəifliyidir. Təsdiqlənmiş MMS sorğu mesajlarında xüsusi hazırlanmış BER elementləri TCP port 102 üzərindən qəbul edildikdə, dekoder daxili oxuma mövqeyini səhv irəlilədə bilər. Bu zəiflikdən istifadə uzaqdan kod icrası və ya xidmət rəddinə səbəb ola biləcəyi üçün təsirlənən SCADA/ICS cihazlarının yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
What must an attacker do to exploit CVE-2026-63550?
The attacker must send specially crafted BER elements within confirmed-request messages over an established MMS session on TCP port 102.
What are the potential consequences of CVE-2026-63550?
Successful exploitation of this vulnerability could lead to remote code execution or denial of service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.