Impact
The vulnerability is an out-of-bounds read (CWE‑125) in the BACnet packet parsing function bacdt_datetime_to_tod. A malformed TimeSynchronization or UTC‑TimeSynchronization packet with an invalid month value can trigger a crash of linx_a64.exe, which in turn causes the device to reboot. This allows an unauthenticated remote attacker to destabilize the device’s availability without needing any credentials.
Affected Systems
Affected products include Loytec LIP‑ME201C, L‑INX, L‑GATE, L‑ROC, L‑IOB, L‑DALI, L‑VIS, and L‑PAD running LINX firmware up to version 8.4.18. Upgrading to firmware 8.4.20 or later resolves the issue for all listed devices.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely over BACnet; an unauthenticated attacker only needs to send a crafted TimeSynchronization packet to the device’s BACnet port.
OpenCVE Enrichment