Back to Database
Status published
High
CVE-2022-2973
MZ Automation libIEC61850 NULL Pointer Dereference
Vulnerability Description
MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) uses a NULL pointer in certain situations. which could allow an attacker to crash the server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-2973
Credits & Attribution
No credits recorded in the NVD database.
More from MZ Automation
View All →CVE-2022-3976
MZ Automation libiec61850 MMS File Services mms_client_files.c path traversal
Medium
5.5
CVE-2022-2972
MZ Automation libIEC61850 Stack-Based Buffer Overflow
Critical
10
CVE-2022-2971
MZ Automation libIEC61850 Access of Resource Using Incompatible Type ('Type Confusion')
High
8.6
CVE-2022-2970
MZ Automation libIEC61850 Stack-Based Buffer Overflow
Critical
10
CVE-2022-1302
Malformed Goose Message in LibIEC61850 may result in a denial of service
High
7.5
Affected Vendor
MZ Automation
View all reports →Affected Software
libIEC61850
Vulnerable Versions:
All, Version 1.5
Timeline
Official Publish:
September 23rd, 2022
Last Modified:
April 16th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H