CVE-2026-32666
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
21/03/2026
Última modificación:
21/03/2026
Descripción
*** Pendiente de traducción *** WebCTRL systems that communicate over BACnet inherit the protocol&#39;s lack<br />
of network layer authentication. WebCTRL does not implement additional <br />
validation of BACnet traffic so an attacker with network access could <br />
spoof BACnet packets directed at either the WebCTRL server or associated<br />
AutomatedLogic controllers. Spoofed packets may be processed as <br />
legitimate.
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA



