vendor:
BACnet Stack
by:
mmorillo
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: BACnet Stack
Affected Version From: bacnet-stack-0.8.6
Affected Version To: bacnet-stack-0.8.6
Patch Exists: YES
Related CWE: CVE-2019-12480
CPE: a:bacnet:bacnet-stack:0.8.6
Platforms Tested: Linux
2019
BACnet Stack 0.8.6 – Denial of Service
The BACnet Stack 0.8.6 is vulnerable to a denial of service attack. This vulnerability allows an attacker to crash the BACnet server by sending a specially crafted packet. The vulnerability has been assigned CVE-2019-12480. After reporting the vulnerability to the vendor, a fix has been released in version 0.8.7 of the BACnet Protocol Stack.
Mitigation:
Upgrade to version 0.8.7 of the BACnet Protocol Stack.