CVE-2026-24060
- EPSS 0.02%
- Veröffentlicht 20.03.2026 23:19:05
- Zuletzt bearbeitet 23.03.2026 16:16:43
Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network tra...
CVE-2026-32666
- EPSS 0.05%
- Veröffentlicht 20.03.2026 23:17:29
- Zuletzt bearbeitet 23.03.2026 16:16:47
WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with network access could spoof BACnet packets directed at ...
CVE-2026-25086
- EPSS 0.02%
- Veröffentlicht 20.03.2026 23:14:23
- Zuletzt bearbeitet 23.03.2026 16:16:43
Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to craft and send malicious packets and impersonate the WebCTRL service without requiring code injection into the WebCTRL software.
- EPSS 0.01%
- Veröffentlicht 22.01.2026 13:16:04
- Zuletzt bearbeitet 15.04.2026 00:35:42
Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows. Storing Passwords in a Recoverable Format vulnerability (CWE-257) in the Web session management component allows an attacker to ac...
CVE-2024-5539
- EPSS 0.08%
- Veröffentlicht 27.11.2025 01:15:46
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation...
CVE-2024-5540
- EPSS 0.09%
- Veröffentlicht 27.11.2025 01:15:46
- Zuletzt bearbeitet 15.04.2026 00:35:42
The reflective cross-site scripting vulnerability found in ALC WebCTRL and Carrier i-Vu in versions older than 8.0 affects login panels allowing a malicious actor to compromise the client browser .
CVE-2025-0657
- EPSS 0.08%
- Veröffentlicht 27.11.2025 01:15:46
- Zuletzt bearbeitet 15.04.2026 00:35:42
A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed packets to be sent through BACnet MS/TP network causing the devices to enter a fault state. This fault state requires a manual po...
CVE-2024-8528
- EPSS 0.04%
- Veröffentlicht 19.11.2025 13:18:35
- Zuletzt bearbeitet 15.04.2026 00:35:42
Reflected XSS using a specific URL in Automated Logic WebCTRL and Carrier i-VU can allow delivery of malicious payload due to a specific GET parameter not being sanitized.
CVE-2024-8527
- EPSS 0.03%
- Veröffentlicht 19.11.2025 13:17:01
- Zuletzt bearbeitet 15.04.2026 00:35:42
Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may allow attackers to exploit user sessions.
- EPSS 1.65%
- Veröffentlicht 21.11.2024 16:15:27
- Zuletzt bearbeitet 15.04.2026 00:35:42
An unrestricted upload of file with dangerous type in Automated Logic WebCTRL 7.0 could allow an unauthenticated user to perform remote command execution via a crafted HTTP POST request which could lead to uploading a malicious file.