Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-12480

Опубликовано: 30 мая 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Средний

Описание

BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. An unauthenticated remote attacker could cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:*:*:*:*:*:*:*:*
Версия до 0.8.6 (включая)

EPSS

Процентиль: 96%
0.21165
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-125

Связанные уязвимости

github
больше 3 лет назад

BACnet Protocol Stack through 0.8.6 could allow an unauthenticated, remote attacker to cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.

EPSS

Процентиль: 96%
0.21165
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-125