Vulnerability Details CVE-2019-12480
BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. An unauthenticated remote attacker could cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.203
EPSS Ranking 95.2%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-12480
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.0.1
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.0.2
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.0.3
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.0.4
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.0.5
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.0.6
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.0.7
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.0.8
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.0.9
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.1.0
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.2.0
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.2.1
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.2.2
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.2.3
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.2.4
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.2.5
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.2.6
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.3.0
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.3.1
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.3.2
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.3.3
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.3.4
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.3.5
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.3.6
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.4.0
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.4.1
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.4.2
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.4.3
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.4.4
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.4.5
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.4.6
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.4.7
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.5.0
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.5.1
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.5.2
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.5.3
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.5.4
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.5.5
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.5.6
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.5.7
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.5.8
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.5.9
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.6.0
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.6.1
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.6.2
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.6.3
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.6.4
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.6.5
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.7.0
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.7.1
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.7.2
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.7.3
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.7.4
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.7.5
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.8.0
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.8.1
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.8.2
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.8.3
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.8.4
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.8.5
-
cpe:2.3:a:bacnet_protocol_stack_project:bacnet_protocol_stack:0.8.6