CVE-2020-36872: BACnet Test Server 1.01 Malformed BVLC Length DoS

Published Nov 26, 2025
·
Updated

BACnet Test Server versions up to and including 1.01 contains a remote denial of service vulnerability in its BACnet/IP BVLC packet handling. The server fails to properly validate the BVLC Length field in incoming UDP BVLC frames on the default BACnet port (47808/udp). A remote unauthenticated attacker can send a malformed BVLC Length value to trigger an access violation and crash the application, resulting in a denial of service.

Affected Software

1 affected component
BACnet Test Server<=1.01

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade BACnet Test Server to a version that resolves this vulnerability.

    Fixed in 1.01
  2. Configuration

    Update BACnet Test Server so it properly validates the BVLC Length field in incoming UDP BVLC frames on the default BACnet port 47808/udp to prevent access-violation crashes (Malformed BVLC Length DoS in versions up to and including 1.01).

    BACnet Test Server BACnet/IP BVLC packet handling (BVLC Length validation for incoming UDP frames on port 47808/udp) = Properly validate BVLC Length field; reject malformed BVLC Length values
  3. Compensating control

    Restrict network access to BACnet Test Server on UDP port 47808 to reduce exposure to remote unauthenticated malformed BVLC frames.

Event History

Nov 26, 2025
CVE Published
via MITRE·10:13 PM
Data Sourced
via MITRE·10:13 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2020-36872?

CVE-2020-36872 has a high severity rating due to the potential for remote denial of service attacks.

2

How do I fix CVE-2020-36872?

To fix CVE-2020-36872, upgrade to a version of BACnet Test Server that is later than 1.01.

3

What type of vulnerability is CVE-2020-36872?

CVE-2020-36872 is a remote denial of service vulnerability related to the handling of BVLC packets.

4

What affected software is related to CVE-2020-36872?

CVE-2020-36872 affects BACnet Test Server versions up to and including 1.01.

5

Can CVE-2020-36872 be exploited remotely?

Yes, CVE-2020-36872 can be exploited remotely due to improper validation of incoming UDP BVLC frames.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203