In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c function of src/mms/iso_mms/server/mms_file_service.c. The vulnerability manifests as SEGV and causes the application to crash
References
| Link | Resource |
|---|---|
| https://github.com/mz-automation/libiec61850/issues/496 | Issue Tracking Third Party Advisory Exploit |
| https://github.com/mz-automation/libiec61850/issues/496 | Issue Tracking Third Party Advisory Exploit |
Configurations
History
02 Jun 2025, 13:59
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Mz-automation
Mz-automation libiec61850 |
|
| CPE | cpe:2.3:a:mz-automation:libiec61850:1.4.0:*:*:*:*:*:*:* | |
| References | () https://github.com/mz-automation/libiec61850/issues/496 - Issue Tracking, Third Party Advisory, Exploit |
21 Nov 2024, 09:06
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/mz-automation/libiec61850/issues/496 - |
05 Aug 2024, 19:35
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-476 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
21 Mar 2024, 02:52
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-03-21 02:52
Updated : 2025-06-02 13:59
NVD link : CVE-2024-28286
Mitre link : CVE-2024-28286
CVE.ORG link : CVE-2024-28286
JSON object : View
Products Affected
mz-automation
- libiec61850
CWE
CWE-476
NULL Pointer Dereference
