Home
HIGH: 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:HDefault status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
0.0.0 (semver)
affected
Description
A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS limited to BACNet communication.
Problem types
CWE-732 Incorrect Permission Assignment for Critical Resource
Product status
0.0.0 (semver)
0.0.0 (semver)
0.0.0 (semver)
0.0.0 (semver)
0.0.0 (semver)
0.0.0 (semver)
0.0.0 (semver)
0.0.0 (semver)
0.0.0 (semver)
0.0.0 (semver)
0.0.0 (semver)
0.0.0 (semver)
0.0.0 (semver)
Credits
Diego Giubertoni
Nozomi Networks
References
cert.vde.com/en/advisories/VDE-2024-047