Impact
A NULL pointer dereference occurs in the libIEC61850 MMS Write Named Variable List handler when flaw can be exploited by an attacker who is in network proximity to crash the server, causing an interruption of the affected service. The vulnerability leads to a loss of availability rather than compromising confidentiality or integrity, which is reflected in the high severity rating. The weakness is a classic null pointer dereference identified as CWE‑476.
Affected Systems
The affected product is MZ Automation’s libIEC61850 library. No specific version numbers are listed, so the issue likely applies to any releases of libIEC61850 prior to the latest build, which the vendor recommends for upgrade.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity level, but the EPSS score of less than 1 % suggests that exploitation is relatively unlikely at this time. The vulnerability is not cataloged in the CISA KEV database. Based on the description, the likely attack vector is a network‑adjacent adversary who can send a crafted MMS WriteRequest to the target. The exploit appears to require no authentication and can be performed from any device that can reach the MMS endpoint.
OpenCVE Enrichment