CVE-2020-36872: BACnet Test Server 1.01 Malformed BVLC Length DoS
BACnet Test Server versions up to and including 1.01 contains a remote denial of service vulnerability in its BACnet/IP BVLC packet handling. The server fails to properly validate the BVLC Length field in incoming UDP BVLC frames on the default BACnet port (47808/udp). A remote unauthenticated attacker can send a malformed BVLC Length value to trigger an access violation and crash the application, resulting in a denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BACnet Test Serverto a version that resolves this vulnerability.Fixed in 1.01 - Configuration
Update BACnet Test Server so it properly validates the BVLC Length field in incoming UDP BVLC frames on the default BACnet port 47808/udp to prevent access-violation crashes (Malformed BVLC Length DoS in versions up to and including 1.01).
BACnet Test Server BACnet/IP BVLC packet handling (BVLC Length validation for incoming UDP frames on port 47808/udp) = Properly validate BVLC Length field; reject malformed BVLC Length values - Compensating control
Restrict network access to BACnet Test Server on UDP port 47808 to reduce exposure to remote unauthenticated malformed BVLC frames.
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36872?
CVE-2020-36872 has a high severity rating due to the potential for remote denial of service attacks.
How do I fix CVE-2020-36872?
To fix CVE-2020-36872, upgrade to a version of BACnet Test Server that is later than 1.01.
What type of vulnerability is CVE-2020-36872?
CVE-2020-36872 is a remote denial of service vulnerability related to the handling of BVLC packets.
What affected software is related to CVE-2020-36872?
CVE-2020-36872 affects BACnet Test Server versions up to and including 1.01.
Can CVE-2020-36872 be exploited remotely?
Yes, CVE-2020-36872 can be exploited remotely due to improper validation of incoming UDP BVLC frames.