CVE-2024-28286

In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c function of src/mms/iso_mms/server/mms_file_service.c. The vulnerability manifests as SEGV and causes the application to crash
References
Link Resource
https://github.com/mz-automation/libiec61850/issues/496 Issue Tracking Third Party Advisory Exploit
https://github.com/mz-automation/libiec61850/issues/496 Issue Tracking Third Party Advisory Exploit
Configurations

Configuration 1 (hide)

cpe:2.3:a:mz-automation:libiec61850:1.4.0:*:*:*:*:*:*:*

History

02 Jun 2025, 13:59

Type Values Removed Values Added
First Time Mz-automation
Mz-automation libiec61850
CPE cpe:2.3:a:mz-automation:libiec61850:1.4.0:*:*:*:*:*:*:*
References () https://github.com/mz-automation/libiec61850/issues/496 - () https://github.com/mz-automation/libiec61850/issues/496 - Issue Tracking, Third Party Advisory, Exploit

21 Nov 2024, 09:06

Type Values Removed Values Added
References () https://github.com/mz-automation/libiec61850/issues/496 - () https://github.com/mz-automation/libiec61850/issues/496 -

05 Aug 2024, 19:35

Type Values Removed Values Added
Summary
  • (es) En mz-automation libiec61850 v1.4.0, se detectó una desreferencia de puntero NULL en la función mmsServer_handleFileCloseRequest.c de src/mms/iso_mms/server/mms_file_service.c. La vulnerabilidad se manifiesta como SEGV y provoca que la aplicación falle.
CWE CWE-476
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

21 Mar 2024, 02:52

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-21 02:52

Updated : 2025-06-02 13:59


NVD link : CVE-2024-28286

Mitre link : CVE-2024-28286

CVE.ORG link : CVE-2024-28286


JSON object : View

Products Affected

mz-automation

  • libiec61850
CWE
CWE-476

NULL Pointer Dereference