---
id: CVE-2026-56758
title: |-
  The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS
   connection establishment
summary: |-
  The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS
   connection establishment. When parsing certain fields within the 
  calling AP title, an attacker controlled length value of zero or one may
   cause the parser to rea…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-125
published: '2026-07-30'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:30:43.093'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56758'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-10.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00295
epssPercentile: 0.19733
ingestedAt: '2026-09-08T20:10:03.155Z'
---

## Overview

The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS
 connection establishment. When parsing certain fields within the 
calling AP title, an attacker controlled length value of zero or one may
 cause the parser to read past the end of a heap buffer.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
