CVE-2026-55732
Loytec · LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI
An out-of-bounds read vulnerability in the BACnet packet parsing function allows unauthenticated remote attackers to trigger a service crash.
Executive summary
A high-severity out-of-bounds read vulnerability in various Loytec automation products can be exploited by remote attackers to cause a denial-of-service condition.
Vulnerability
This vulnerability involves an out-of-bounds read (CWE-125) within the BACnet packet parsing logic, specifically in the function bacdt_datetime_to_tod. The flaw is remotely exploitable by an unauthenticated attacker, allowing them to crash the affected device by sending a specially crafted packet.
Business impact
The successful exploitation of this vulnerability results in a denial-of-service, which leads to significant system downtime for critical building automation infrastructure. Given the CVSS score of 8.7, this is considered high risk, as it impacts the availability of core operational technology systems that may be difficult to recover without manual intervention.
Remediation
Immediate Action: Upgrade all affected devices to firmware version 8.4.20 immediately.
Proactive Monitoring: Monitor network traffic for malformed BACnet packets and review system logs for unexpected crashes or service restarts.
Compensating Controls: Restrict network access to BACnet devices by placing them behind a firewall or within a segmented VLAN to ensure only authorized traffic can reach these interfaces.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the nature of the affected industrial hardware, organizations should prioritize the firmware update process. Immediate patching is necessary to prevent potential service disruption caused by malicious actors targeting BACnet communication protocols.