CVE-2020-36872: Bacnet Interoperability Test Services, Inc Bacnet Test Server

High severity, CVSS 8.7. EPSS: 0.5% chance of exploitation in the next 30 days.

BACnet Test Server versions up to and including 1.01 contains a remote denial of service vulnerability in its BACnet/IP BVLC packet handling. The server fails to properly validate the BVLC Length field in incoming UDP BVLC frames on the default BACnet port (47808/udp). A remote unauthenticated attacker can send a malformed BVLC Length value to trigger an access violation and crash the application, resulting in a denial of service.

Affected products

Published 2025-11-26. Last modified 2026-06-17.