CVE-2026-50103CWE-228

Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850

High · published July 23, 2026

CVSS v4.0
7.1
EPSS
0%
Percentile
18.7
In the wild
Unconfirmed
What it is

A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value.

The record
Technical detail
CVSS v4.0
7.1 · HIGH
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
0.00269 · 18.7th percentile
Weakness
CWE-228 · Improper Handling of Syntactically Invalid Structure
Published
2026-07-23T20:50Z
EPSS history
Timeline
  • 23 JUL 20:50Z
    Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850
    cvelistv5