In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c function of src/mms/iso_mms/server/mms_file_service.c. The vulnerability manifests as SEGV and causes the application to crash
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/mz-automation/libiec61850/issues/496 | Issue Tracking Third Party Advisory Exploit | 
| https://github.com/mz-automation/libiec61850/issues/496 | Issue Tracking Third Party Advisory Exploit | 
Configurations
                    History
                    02 Jun 2025, 13:59
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | 
        
        Mz-automation
         Mz-automation libiec61850  | 
|
| CPE | cpe:2.3:a:mz-automation:libiec61850:1.4.0:*:*:*:*:*:*:* | |
| References | () https://github.com/mz-automation/libiec61850/issues/496 - Issue Tracking, Third Party Advisory, Exploit | 
21 Nov 2024, 09:06
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/mz-automation/libiec61850/issues/496 - | 
05 Aug 2024, 19:35
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-476 | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 7.5  | 
21 Mar 2024, 02:52
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-03-21 02:52
Updated : 2025-06-02 13:59
NVD link : CVE-2024-28286
Mitre link : CVE-2024-28286
CVE.ORG link : CVE-2024-28286
JSON object : View
Products Affected
                mz-automation
- libiec61850
 
CWE
                
                    
                        
                        CWE-476
                        
            NULL Pointer Dereference
