CVE-2019-12480: Bacnet Protocol Stack Project Bacnet Protocol Stack
High severity, CVSS 7.5. EPSS: 33.9% chance of exploitation in the next 30 days.
BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. An unauthenticated remote attacker could cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.
Affected products
- Bacnet Protocol Stack Project Bacnet Protocol Stack: up to and including 0.8.6
Published 2019-05-30. Last modified 2026-06-17.