CVE-2023-51773
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/02/2024
Last modified:
23/05/2025
Description
BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:bacnetstack:bacnet_stack:*:*:*:*:*:*:*:* | 1.3.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/bacnet-stack/bacnet-stack/blob/master/CHANGELOG.md
- https://github.com/bacnet-stack/bacnet-stack/compare/bacnet-stack-1.3.1...bacnet-stack-1.3.2
- https://github.com/bacnet-stack/bacnet-stack/pull/546
- https://github.com/bacnet-stack/bacnet-stack/pull/546/commits/c465412a076ca6c9ddf649612f2b4e1874d8dcb8
- https://sourceforge.net/p/bacnet/bugs/85/
- https://github.com/bacnet-stack/bacnet-stack/blob/master/CHANGELOG.md
- https://github.com/bacnet-stack/bacnet-stack/compare/bacnet-stack-1.3.1...bacnet-stack-1.3.2
- https://github.com/bacnet-stack/bacnet-stack/pull/546
- https://github.com/bacnet-stack/bacnet-stack/pull/546/commits/c465412a076ca6c9ddf649612f2b4e1874d8dcb8
- https://sourceforge.net/p/bacnet/bugs/85/



