Home

Description

A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The device enters a fault state; after a reset, a second packet can leave it permanently unresponsive until a manual power cycle is performed.

PUBLISHED Reserved 2025-01-22 | Published 2025-11-27 | Updated 2025-11-28 | Assigner Carrier




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-20 Improper Input Validation

Product status

Default status
unaffected

Any version before 6.06-101
affected

Default status
unaffected

Any version before 6.06-101
affected

Credits

Christopher Morales Gonzalez reporter

References

https/....carrier.com/product-security/advisories-resources/

cve.org (CVE-2025-0658)

nvd.nist.gov (CVE-2025-0658)

Download JSON