Low Privileged Remote Attacker Can Modify BACNet Service Properties, Leading to Denial of Service
CVE-2024-41974

7.1HIGH

What is CVE-2024-41974?

A remote code execution vulnerability exists in the BACNet service of Vendor XYZ that allows low privileged attackers to alter service properties. This flaw arises from improper permission assignments for essential resources. Exploitation of this vulnerability could lead to a denial of service, specifically disrupting BACNet communication, which can affect the operation of systems relying on this protocol. Organizations using affected BACNet versions should review their configurations and apply the necessary defenses to mitigate potential risks.

Affected Version(s)

CC100 0751-9x01 0.0.0 <= 4.5.10 (FW27)

CC100 0751/9x01 0.0.0 <= 04.03.03 (72)

CC100 0751/9x01 0.0.0 <= 04.04.03 (70)

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Credit

Diego Giubertoni
Nozomi Networks
.