BACnet Protocol Stack through 0.8.6 has a segmentation fault leading...
Vulnerability Description
BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. An unauthenticated remote attacker could cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-12480
Credits & Attribution
No credits recorded in the NVD database.
References
- https://sourceforge.net/p/bacnet/bugs/62/
- https://sourceforge.net/p/bacnet/code/3220
- https://sourceforge.net/p/bacnet/code/3223
- https://sourceforge.net/p/bacnet/code/3224
- https://sourceforge.net/p/bacnet/code/3225
- http://packetstormsecurity.com/files/153716/BACnet-Stack-0.8.6-Denial-Of-Service.html
- https://1modm.github.io/CVE-2019-12480.html
More from bacnet protocol stack project
View All →Affected Vendor
bacnet protocol stack project
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.