CVE-2026-24060
Severity CVSS v4.0:
Pending analysis
Type:
CWE-319
Cleartext Transmission of Sensitive Information
Publication date:
21/03/2026
Last modified:
23/03/2026
Description
Service information is not encrypted when transmitted as BACnet packets <br />
over the wire, and can be sniffed, intercepted, and modified by an <br />
attacker. Valuable information such as the File Start Position and File <br />
Data can be sniffed from network traffic using Wireshark&#39;s BACnet <br />
dissector filter. The proprietary format used by WebCTRL to receive <br />
updates from the PLC can also be sniffed and reverse engineered.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL



