CVE-2026-50103CWE-228
Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850
High · published July 23, 2026
What it is
A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value.
The record
Technical detail
- CVSS v4.0
- 7.1 · HIGH
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS
- 0.00269 · 18.7th percentile
- Weakness
- CWE-228 · Improper Handling of Syntactically Invalid Structure
- Published
- 2026-07-23T20:50Z
EPSS history
Timeline