CVE-2026-24060

Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network traffic using Wireshark's BACnet dissector filter. The proprietary format used by WebCTRL to receive updates from the PLC can also be sniffed and reverse engineered.
Configurations

No configuration.

History

17 Jun 2026, 10:22

Type Values Removed Values Added
Summary
  • (es) La información de servicio no está cifrada cuando se transmite como paquetes BACnet a través de la red, y puede ser olfateada, interceptada y modificada por un atacante. Información valiosa como la Posición de Inicio del Archivo y los Datos del Archivo puede ser olfateada del tráfico de red utilizando el filtro disector BACnet de Wireshark. El formato propietario utilizado por WebCTRL para recibir actualizaciones del PLC también puede ser olfateado y sometido a ingeniería inversa.

21 Mar 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 00:16

Updated : 2026-06-17 10:22


NVD link : CVE-2026-24060

Mitre link : CVE-2026-24060

CVE.ORG link : CVE-2026-24060


JSON object : View

Products Affected

No product.

CWE
CWE-319

Cleartext Transmission of Sensitive Information