NULL pointer dereference in libIEC61850 - CVE-2026-48741
Published: June 18, 2026
libIEC61850
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in alternateArrayAccess() in the MMS read service when processing out-of-range sub-array read requests using alternate-access indexRange. A remote attacker can send a specially crafted MMS Read request to cause a denial of service.
Only MMS server implementations that use data models containing arrays are vulnerable.