CVE-2026-24060

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
21/03/2026
Last modified:
23/03/2026

Description

Service information is not encrypted when transmitted as BACnet packets <br /> over the wire, and can be sniffed, intercepted, and modified by an <br /> attacker. Valuable information such as the File Start Position and File <br /> Data can be sniffed from network traffic using Wireshark&amp;#39;s BACnet <br /> dissector filter. The proprietary format used by WebCTRL to receive <br /> updates from the PLC can also be sniffed and reverse engineered.