HIGH

CVE-2019-12480

CVSS v3

7.5

HIGH

EPSS Score

21.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. An unauthenticated remote attacker could cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.

Technical details

Published
5/30/2019
Exploit-DB
EDB-47148

Frequently asked questions

What is CVE-2019-12480?

BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. An unauthenticated remote attacker could cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.

Is CVE-2019-12480 actively exploited?

Active exploitation of CVE-2019-12480 has not been confirmed. The EPSS score is 21.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-12480?

CVE-2019-12480 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2019-12480 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.