Home/Product/bacnetstack bacnet stack
Product

bacnetstack bacnet stack

9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-41503
>= 1.4.0 and < 1.4.3
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerab
7.5HIGH
CVE-2026-41502
>= 1.4.0 and < 1.4.3
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an off-by-one out-of-bounds re
7.5HIGH
CVE-2026-41475
>= 1.4.0 and < 1.4.3
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerab
9.1CRITICAL
CVE-2026-40279
< 1.4.3
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, decode_signed32() in src/bacne
3.7LOW
CVE-2026-26264
>= 1.4.0 and < 1.4.3
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0rc4 and 1.4.3rc2, a malformed Wr
8.1HIGH
CVE-2026-21878
all versions
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability has been d
7.5HIGH
CVE-2026-21870
<= 1.4.2
BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communications servi
5.5MEDIUM
CVE-2025-66624
all versions
BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communications servi
7.5HIGH
CVE-2023-51773
< 1.3.2
BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c.
9.1CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin