{"id":"CVE-2026-56758","title":"The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS\n connection establishment","summary":"The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS\n connection establishment. When parsing certain fields within the \ncalling AP title, an attacker controlled length value of zero or one may\n cause the parser to rea…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-125"],"published":"2026-07-30","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:30:43.093","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-56758","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-10.json","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10","label":"ics-cert@hq.dhs.gov"}],"tags":["nvd"],"epss":0.00181,"epssPercentile":0.07916,"ingestedAt":"2026-09-08T20:10:03.155Z","slug":"CVE-2026-56758","body":"## Overview\n\nThe ACSE layer contains a flaw in the processing of AARQ PDUs during MMS\n connection establishment. When parsing certain fields within the \ncalling AP title, an attacker controlled length value of zero or one may\n cause the parser to read past the end of a heap buffer.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}