CVE-2026-24060
Automated Logic WebCTRL Premium Server Cleartext Transmission of Sensitive Information
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.1EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
20 mar 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Service information is not encrypted when transmitted as BACnet packets
over the wire, and can be sniffed, intercepted, and modified by an
attacker. Valuable information such as the File Start Position and File
Data can be sniffed from network traffic using Wireshark's BACnet
dissector filter. The proprietary format used by WebCTRL to receive
updates from the PLC can also be sniffed and reverse engineered.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Productos afectados
Automated Logic · WebCTRL Premium Server¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →