The BACnet Protocol Stack Project maintains a specialized open-source implementation of the BACnet building-automation protocol, which operates within a narrowly scoped but critical niche in industrial control and HVAC management systems. Observed vulnerabilities center on memory-safety issues including buffer-boundary violations and out-of-bounds reads, reflecting the low-level parsing demands of embedded protocol implementations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bacnet Protocol Stack Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12480HIGH BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and Device | May 30, 2019 | 7.5 | 53 | NO | YES |
CVE-2018-10238CRITICAL bvlc.c in skarg BACnet Protocol Stack bacserv 0.9.1 and 0.8.5 is affected by a Buffer Overflow because of a lack of packet-size validation. The affected component is bacserv BACnet | Apr 20, 2018 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bacnet Protocol Stack Project.
Media articles that mention a CVE ID that affects a product developed by Bacnet Protocol Stack Project — matched by CVE ID, not by vendor name.