Vulnerability Description
BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. An unauthenticated remote attacker could cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bacnet Protocol Stack Project | Bacnet Protocol Stack | <= 0.8.6 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/153716/BACnet-Stack-0.8.6-Denial-Of-Service
- https://1modm.github.io/CVE-2019-12480.html
- https://sourceforge.net/p/bacnet/bugs/62/ExploitThird Party Advisory
- https://sourceforge.net/p/bacnet/code/3220
- https://sourceforge.net/p/bacnet/code/3223
- https://sourceforge.net/p/bacnet/code/3224
- https://sourceforge.net/p/bacnet/code/3225
- http://packetstormsecurity.com/files/153716/BACnet-Stack-0.8.6-Denial-Of-Service
- https://1modm.github.io/CVE-2019-12480.html
- https://sourceforge.net/p/bacnet/bugs/62/ExploitThird Party Advisory
- https://sourceforge.net/p/bacnet/code/3220
- https://sourceforge.net/p/bacnet/code/3223
- https://sourceforge.net/p/bacnet/code/3224
- https://sourceforge.net/p/bacnet/code/3225
FAQ
What is CVE-2019-12480?
CVE-2019-12480 is a vulnerability with a CVSS score of 7.5 (HIGH). BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl...
How severe is CVE-2019-12480?
CVE-2019-12480 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12480?
Check the references section above for vendor advisories and patch information. Affected products include: Bacnet Protocol Stack Project Bacnet Protocol Stack.