CVE-2023-51773: Bacnetstack Bacnet Stack

Critical severity, CVSS 9.1. EPSS: 1.1% chance of exploitation in the next 30 days.

BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c.

Affected products

  • Bacnetstack Bacnet Stack: before 1.3.2 (fixed in 1.3.2)

Published 2024-02-29. Last modified 2026-06-17.