CVE-2019-12480: Bacnet Protocol Stack Project Bacnet Protocol Stack

High severity, CVSS 7.5. EPSS: 33.9% chance of exploitation in the next 30 days.

BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. An unauthenticated remote attacker could cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.

Affected products

Published 2019-05-30. Last modified 2026-06-17.