CVE-2021-45769: Null Pointer Dereference
Published Jan 14, 2022
·Updated
A NULL pointer dereference in AcseConnectionparseMessage at src/mms/isoacse/acse.c of libiec61850 v1.5.0 can lead to a segmentation fault or application crash.
Affected Software
1 affected component
mz-automation libiec61850=1.5.0
Remediation
Patch Available
Event History
Jan 14, 2022
CVE Published
via MITRE·07:10 PM
Data Sourced
via MITRE·07:10 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-45769?
CVE-2021-45769 has a medium severity level due to potential application crashes caused by NULL pointer dereference.
2
How do I fix CVE-2021-45769?
To fix CVE-2021-45769, update libiec61850 to version 1.5.1 or later where the vulnerability is addressed.
3
Who is affected by CVE-2021-45769?
Users of libiec61850 version 1.5.0 are primarily affected by CVE-2021-45769.
4
What can exploiters do with CVE-2021-45769?
Exploiters can cause a segmentation fault leading to application instability by triggering the NULL pointer dereference in CVE-2021-45769.
5
Is CVE-2021-45769 easy to exploit?
Yes, CVE-2021-45769 can be easily exploited if the attacker can send crafted messages to a vulnerable instance of libiec61850.