CVE-2024-28286: Null Pointer Dereference
Published Mar 20, 2024
·Updated
In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServerhandleFileCloseRequest.c function of src/mms/isomms/server/mmsfileservice.c. The vulnerability manifests as SEGV and causes the application to crash
Affected Software
2 affected components
mz-automation libiec61850
mz-automation libiec61850=1.4.0
Event History
Mar 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Mar 21, 2024
Data Sourced
via NVD·02:52 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28286?
CVE-2024-28286 has a high severity due to its potential to cause application crashes through a NULL Pointer Dereference.
2
How do I fix CVE-2024-28286?
To fix CVE-2024-28286, update mz-automation libiec61850 to a version that addresses this vulnerability.
3
What systems are affected by CVE-2024-28286?
CVE-2024-28286 affects mz-automation libiec61850 version 1.4.0.
4
What is the impact of CVE-2024-28286?
The impact of CVE-2024-28286 is an application crash that occurs due to a segment violation.
5
Is there a workaround for CVE-2024-28286?
Currently, there are no known workarounds for CVE-2024-28286 other than upgrading to a patched version.