CVE-2026-24060
CRITICALCVSS 9.1/10EPSS 0.20%
Last modified
This CVE is reserved or awaiting analysis. Details will appear once published by NVD.
Description
Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network traffic using Wireshark's BACnet dissector filter. The proprietary format used by WebCTRL to receive updates from the PLC can also be sniffed and reverse engineered.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Are you affected by CVE-2026-24060?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
