Impact
A crafted GOOSE frame containing a malformed TLV value can trigger a NULL pointer dereference in the L2 GOOSE and R‑GOOSE shared parser of libIEC61850. This flaw will crash a subscribing application, resulting in a denial of available control and monitoring functions.
Affected Systems
The vulnerability affects the libIEC61850 library developed by MZ Automation. All installations using this library and processing GOOSE or R‑GOOSE frames are potentially impacted; specific version information is not provided, but any build prior to the latest release is likely vulnerable.
Risk and Exploitability
The CVSS score of 7.1 reflects a high severity level. Based on the EPSS score being less than 1%, the likelihood of exploitation is considered low, and the flaw has not been published in the CISA KEV catalog. However, since the vulnerability can be triggered by network‑adjacent traffic, systems that receive GOOSE frames from untrusted networks are at risk. The attack vector is inferred to be network based, requiring an attacker to send a specially crafted frame to a subscribing device.
OpenCVE Enrichment