Vulnerabilidades em bacnet-stack
8 resultadosAnálise Vexday
O bacnet-stack apresenta um perfil de risco moderado com 8 vulnerabilidades catalogadas, nenhuma delas sob exploração ativa no momento. A ausência de CVEs críticos (CVSS) e publicações recentes sugere que o risco é predominantemente técnico e legado, concentrado em leitura fora dos limites (CWE-125), típico de análise de buffer em código C. Organizações usando este componente devem priorizar testes de segurança e análise estática, mas não enfrentam ameaça imediata.
CVE-2026-41475HIGHBACnet Stack: Out-of-Bounds Read in WritePropertyMultiple Decoder via Deprecated Tag ParserEPSS 0.5%CVE-2026-41503HIGHBACnet Stack: Out-of-Bounds Read in ReadPropertyMultiple Property Decoder via Deprecated Tag ParserEPSS 0.4%CVE-2026-41502HIGHBACnet Stack: Off-by-One Out-of-Bounds Read in ReadPropertyMultiple Object ID DecoderEPSS 0.4%CVE-2026-26264HIGHBACnet Stack WriteProperty decoding length underflow leads to OOB read and crashEPSS 0.4%CVE-2025-66624HIGHBACnet-stack MS/TP reply matcher OOB readEPSS 0.4%CVE-2026-21878HIGHBACnet Stack Improperly Limits Pathnames to a Restricted DirectoryEPSS 0.4%CVE-2026-40279LOWBACnet Stack: Undefined-behavior signed left shift in `decode_signed32()`EPSS 0.2%CVE-2026-21870MEDIUMThe BACnet Protocol Stack library has an Off-by-one Stack-based Buffer Overflow in tokenizer_stringEPSS 0.2%