Description
A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value.
Published: 2026-07-23
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A crafted GOOSE frame containing a malformed TLV value can trigger a NULL pointer dereference in the L2 GOOSE and R‑GOOSE shared parser of libIEC61850. This flaw will crash a subscribing application, resulting in a denial of available control and monitoring functions.

Affected Systems

The vulnerability affects the libIEC61850 library developed by MZ Automation. All installations using this library and processing GOOSE or R‑GOOSE frames are potentially impacted; specific version information is not provided, but any build prior to the latest release is likely vulnerable.

Risk and Exploitability

The CVSS score of 7.1 reflects a high severity level. Based on the EPSS score being less than 1%, the likelihood of exploitation is considered low, and the flaw has not been published in the CISA KEV catalog. However, since the vulnerability can be triggered by network‑adjacent traffic, systems that receive GOOSE frames from untrusted networks are at risk. The attack vector is inferred to be network based, requiring an attacker to send a specially crafted frame to a subscribing device.

Generated by OpenCVE AI on August 3, 2026 at 20:57 UTC.

Remediation

Vendor Solution

MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850. https://github.com/mz-automation/libiec61850


OpenCVE Recommended Actions

  • Update to the latest libIEC61850 release provided by MZ Automation
  • If an update cannot be applied immediately, isolate the affected system from untrusted network segments to block crafted GOOSE traffic
  • Enable detailed logging of crash events and monitor for repeated GOOSE frame rejections to detect attempted exploitation

Generated by OpenCVE AI on August 3, 2026 at 20:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Mz-automation
Mz-automation libiec61850
Vendors & Products Mz-automation
Mz-automation libiec61850

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value.
Title Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850
Weaknesses CWE-228
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mz-automation Libiec61850
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-24T13:41:40.192Z

Reserved: 2026-06-09T20:01:29.578Z

Link: CVE-2026-50103

cve-icon Vulnrichment

Updated: 2026-07-24T13:41:36.335Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T21:17:05.057

Modified: 2026-07-30T14:12:18.697

Link: CVE-2026-50103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:00:12Z

Weaknesses
  • CWE-228

    Improper Handling of Syntactically Invalid Structure