CVE-2019-12480
HIGHBacnet Protocol Stack < 0.8.6 - Out-of-Bounds Read
Title source: ruleDescription
BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. An unauthenticated remote attacker could cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.
Exploits (1)
References (7)
Scores
CVSS v3
7.5
EPSS
0.1547
EPSS Percentile
94.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-125
Status
published
Products (1)
bacnet_protocol_stack_project/bacnet_protocol_stack
< 0.8.6
Published
May 30, 2019
Tracked Since
Feb 18, 2026