Low Privileged Remote Attacker Can Modify BACNet Service Properties, Leading to Denial of Service
CVE-2024-41974
7.1HIGH
What is CVE-2024-41974?
A remote code execution vulnerability exists in the BACNet service of Vendor XYZ that allows low privileged attackers to alter service properties. This flaw arises from improper permission assignments for essential resources. Exploitation of this vulnerability could lead to a denial of service, specifically disrupting BACNet communication, which can affect the operation of systems relying on this protocol. Organizations using affected BACNet versions should review their configurations and apply the necessary defenses to mitigate potential risks.
Affected Version(s)
CC100 0751-9x01 0.0.0 <= 4.5.10 (FW27)
CC100 0751/9x01 0.0.0 <= 04.03.03 (72)
CC100 0751/9x01 0.0.0 <= 04.04.03 (70)