CVE-2025-40556: Input Validation
A vulnerability has been identified in BACnet ATEC 550-440 (All versions), BACnet ATEC 550-441 (All versions), BACnet ATEC 550-445 (All versions), BACnet ATEC 550-446 (All versions). Affected devices improperly handle specific incoming BACnet MSTP messages. This could allow an attacker residing in the same BACnet network to send a specially crafted MSTP message that results in a denial of service condition of the targeted device. A power cycle is required to restore the device's normal operation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40556?
CVE-2025-40556 is considered to have a significant severity due to the potential for unauthorized access through improper handling of BACnet MSTP messages.
How do I fix CVE-2025-40556?
To mitigate CVE-2025-40556, users should apply any available patches or updates from the vendor and implement network segmentation to limit exposure.
What products are affected by CVE-2025-40556?
CVE-2025-40556 affects BACnet ATEC 550-440, BACnet ATEC 550-441, BACnet ATEC 550-445, and BACnet ATEC 550-446, all versions.
Can CVE-2025-40556 be exploited remotely?
Yes, CVE-2025-40556 can potentially be exploited remotely by an attacker within the same network.
What types of attacks are associated with CVE-2025-40556?
CVE-2025-40556 may allow attackers to execute unauthorized commands or gain control over affected devices through specially crafted BACnet MSTP messages.