Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2019-12480

Description

BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. An unauthenticated remote attacker could cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.

POC

Reference

- http://packetstormsecurity.com/files/153716/BACnet-Stack-0.8.6-Denial-Of-Service.html

- https://1modm.github.io/CVE-2019-12480.html

Github

- https://github.com/DSKPutra/All-About-OT-Security

- https://github.com/Orange-Cyberdefense/awesome-industrial-protocols

- https://github.com/biero-el-corridor/OT_ICS_ressource_list

- https://github.com/neutrinoguy/awesome-ics-writeups

- https://github.com/paulveillard/cybersecurity-OT

- https://github.com/whoami-chmod777/Awesome-Industrial-Protocols