CyberRota Analysis
AI-GeneratedLoytec devices, including the LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, and L-PAD, are vulnerable to an out-of-bounds read issue in BACnet packet parsing, which can be exploited by unauthenticated remote attackers. By sending a malformed BACnet TimeSynchronization packet with an invalid month value, an attacker can crash the `linx_a64.exe` process, potentially leading to device reboot and service disruption. Organizations using these Loytec products should prioritize patching to mitigate the risk of remote exploitation and ensure operational continuity.
Original NVD Description
Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash `linx_a64.exe` and ultimately reboot the device via a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet with an invalid month value. The same vulnerability affects multiple other Loytec products.