CVE-2019-12480
CVE-2019-12480
BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. An unauthenticated remote attacker could cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 2
cve_referencepacketstormsecurity.com/files/153716/BACnet-Stack-0.8.6-Denial-Of-Service.htmlnão verificadoexploitdbwww.exploit-db.com/exploits/47148não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://packetstormsecurity.com/files/153716/BACnet-Stack-0.8.6-Denial-Of-Service.htmlhttps://1modm.github.io/CVE-2019-12480.htmlhttps://sourceforge.net/p/bacnet/bugs/62/https://sourceforge.net/p/bacnet/code/3220https://sourceforge.net/p/bacnet/code/3223https://sourceforge.net/p/bacnet/code/3224https://sourceforge.net/p/bacnet/code/3225