PT-2026-35074 · Unknown · Bacnet Stack

Published

2026-04-24

·

Updated

2026-04-25

·

CVE-2026-41475

CVSS v4.0

8.7

High

AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions BACnet Stack versions prior to 1.4.3
Description An out-of-bounds read exists in the WritePropertyMultiple service decoder. This occurs because the wpm decode object property() function calls the deprecated decode tag number and value() function, which lacks bounds checking on the input buffer. An unauthenticated remote attacker can send a crafted BACnet/IP packet with a truncated property payload to read 1-7 bytes beyond the allocated buffer boundaries, potentially leading to information disclosure or system crashes on embedded devices.
Recommendations Update to version 1.4.3.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-41475

Affected Products

Bacnet Stack