CVE-2019-12480
HIGHBACnet Protocol Stack <= 0.8.6 - Unauthenticated Denial of Service via Malformed DCC in AtomicWriteFile
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-12480. PoCs published by mmorillo.
AI-analyzed exploit summary This exploit sends malformed BACnet protocol packets to trigger a segmentation fault in BACnet Stack 0.8.6, leading to a denial of service (DoS). It uses UDP sockets to send three distinct payloads targeting DeviceCommunicationControl, AtomicReadFile, and AtomicWriteFile services.
Description
BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. An unauthenticated remote attacker could cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.
Exploits (1)
This exploit sends malformed BACnet protocol packets to trigger a segmentation fault in BACnet Stack 0.8.6, leading to a denial of service (DoS). It uses UDP sockets to send three distinct payloads targeting DeviceCommunicationControl, AtomicReadFile, and AtomicWriteFile services.
References (7)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H