CVE-2026-32666
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/03/2026
Last modified:
21/03/2026
Description
WebCTRL systems that communicate over BACnet inherit the protocol&#39;s lack<br />
of network layer authentication. WebCTRL does not implement additional <br />
validation of BACnet traffic so an attacker with network access could <br />
spoof BACnet packets directed at either the WebCTRL server or associated<br />
AutomatedLogic controllers. Spoofed packets may be processed as <br />
legitimate.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



