216.73.217.22

CVE-2026-41475

· Published 24/04/2026 20:16 · Modified 24/04/2026 20:16

Labels: CVE-2026-41475 2026-04-24CVE-2026-41475CWE-125[email protected]

Essential information

Published
24/04/2026 20:16
Modified
24/04/2026 20:16
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-stack's WritePropertyMultiple service decoder allows unauthenticated remote attackers to read past allocated buffer boundaries by sending a truncated WPM request. The vulnerability stems from wpm_decode_object_property() calling the deprecated decode_tag_number_and_value() function, which performs no bounds checking on the input buffer. A crafted BACnet/IP packet with a truncated property payload causes the decoder to read 1-7 bytes past the end of the buffer, leading to crashes or information disclosure on embedded BACnet devices. This vulnerability is fixed in 1.4.3.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
bacnet / bacnet stack cpe:2.3:a:bacnet:bacnet_stack:*:*:*:*:*:*:*:*
bacnet / bacnet stack cpe:2.3:a:bacnet:bacnet_stack:<1.4.3:*:*:*:*:*:*:*

References