CVE-2026-32666

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/03/2026
Last modified:
21/03/2026

Description

WebCTRL systems that communicate over BACnet inherit the protocol&amp;#39;s lack<br /> of network layer authentication. WebCTRL does not implement additional <br /> validation of BACnet traffic so an attacker with network access could <br /> spoof BACnet packets directed at either the WebCTRL server or associated<br /> AutomatedLogic controllers. Spoofed packets may be processed as <br /> legitimate.