Vulnerability record · CVE-2018-10238 · published 20 April 2018
CVE-2018-10238: Bacnet protocol stack project bacnet protocol stack memory buffer overflow vulnerability
Bacnet Protocol Stack Project · Bacnet Protocol Stack
bvlc.c in skarg BACnet Protocol Stack bacserv 0.9.1 and 0.8.5 is affected by a Buffer Overflow because of a lack of packet-size validation. The affected component is bacserv BACnet/IP BVLC forwarded NPDU. The function bvlc_bdt_forward_npdu() calls bvlc_encode_forwarded_npdu() which copies the content from the request into a local in the bvlc_bdt_forward_npdu() stack frame and clobbers the canary. The attack vector is: A BACnet/IP device with BBMD enabled based on this library connected to IP network. The fixed version is: 0.8.6.
Description
bvlc.c in skarg BACnet Protocol Stack bacserv 0.9.1 and 0.8.5 is affected by a Buffer Overflow because of a lack of packet-size validation. The affected component is bacserv BACnet/IP BVLC forwarded NPDU. The function bvlc_bdt_forward_npdu() calls bvlc_encode_forwarded_npdu() which copies the content from the request into a local in the bvlc_bdt_forward_npdu() stack frame and clobbers the canary. The attack vector is: A BACnet/IP device with BBMD enabled based on this library connected to IP network. The fixed version is: 0.8.6.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sourceforge.net/p/bacnet/bugs/55/ | |
| https://sourceforge.net/p/bacnet/code/3168/ | PatchThird Party Advisory |
| https://sourceforge.net/p/bacnet/code/3169/ | |
| https://sourceforge.net/p/bacnet/bugs/55/ | |
| https://sourceforge.net/p/bacnet/code/3168/ | PatchThird Party Advisory |
| https://sourceforge.net/p/bacnet/code/3169/ |
Track CVE-2018-10238 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-10238), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.