Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-79hg-m6px-6m7h

Опубликовано: 21 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network traffic using Wireshark's BACnet dissector filter. The proprietary format used by WebCTRL to receive updates from the PLC can also be sniffed and reverse engineered.

Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network traffic using Wireshark's BACnet dissector filter. The proprietary format used by WebCTRL to receive updates from the PLC can also be sniffed and reverse engineered.

EPSS

Процентиль: 3%
0.00016
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 9.1
nvd
24 дня назад

Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network traffic using Wireshark's BACnet dissector filter. The proprietary format used by WebCTRL to receive updates from the PLC can also be sniffed and reverse engineered.

EPSS

Процентиль: 3%
0.00016
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-319