PT-2024-7570 · Unknown · Libiec61850
Alice-And-Bob
·
Published
2024-03-20
·
Updated
2025-06-02
·
CVE-2024-28286
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
libiec61850 version 1.4.0
Description
A NULL Pointer Dereference issue was detected in the
mmsServer handleFileCloseRequest.c function of src/mms/iso mms/server/mms file service.c, which can cause the application to crash due to a SEGV. The vulnerability is related to pointer dereference errors in the libIEC61850 library. Exploitation of this issue may allow an attacker to cause a denial of service.Recommendations
For libiec61850 version 1.4.0, as a temporary workaround, consider disabling the
mmsServer handleFileCloseRequest.c function until a patch is available. Restrict access to the mms file service.c module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libiec61850