Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2v87-3m5p-q6cw

Опубликовано: 21 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with network access could spoof BACnet packets directed at either the WebCTRL server or associated AutomatedLogic controllers. Spoofed packets may be processed as legitimate.

WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with network access could spoof BACnet packets directed at either the WebCTRL server or associated AutomatedLogic controllers. Spoofed packets may be processed as legitimate.

EPSS

Процентиль: 16%
0.00051
Низкий

7.5 High

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 7.5
nvd
25 дней назад

WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with network access could spoof BACnet packets directed at either the WebCTRL server or associated AutomatedLogic controllers. Spoofed packets may be processed as legitimate.

EPSS

Процентиль: 16%
0.00051
Низкий

7.5 High

CVSS3

Дефекты

CWE-290