Low Privileged Remote Attacker Can Modify BACNet Service Properties, Leading to Denial of Service
CVE-2024-41974
7.1HIGH
What is CVE-2024-41974?
A remote code execution vulnerability exists in the BACNet service of Vendor XYZ that allows low privileged attackers to alter service properties. This flaw arises from improper permission assignments for essential resources. Exploitation of this vulnerability could lead to a denial of service, specifically disrupting BACNet communication, which can affect the operation of systems relying on this protocol. Organizations using affected BACNet versions should review their configurations and apply the necessary defenses to mitigate potential risks.
Affected Version(s)
CC100 0751-9x01 0.0.0 <= 4.5.10 (FW27)
CC100 0751/9x01 0.0.0 <= 04.03.03 (72)
CC100 0751/9x01 0.0.0 <= 04.04.03 (70)
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Credit
Diego Giubertoni
Nozomi Networks
