{"gsd":{"metadata":{"exploitCode":"unknown","remediation":"unknown","reportConfidence":"confirmed","type":"vulnerability"},"osvSchema":{"aliases":["CVE-2024-4292"],"details":"A vulnerability classified as critical has been found in Contemporary Controls BASrouter BACnet BASRT-B 2.7.2. Affected is an unknown function of the component Device-Communication-Control Service. The manipulation with the input 55ff0500370015f30104025506110afb7519035d0841e4bece257b6acfc71f leads to denial of service. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-262224. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.","id":"GSD-2024-4292","modified":"2024-04-28T05:02:06.073286Z","schema_version":"1.4.0"}},"namespaces":{"cve.org":{"CVE_data_meta":{"ASSIGNER":"cna@vuldb.com","ID":"CVE-2024-4292","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"BASrouter BACnet BASRT-B","version":{"version_data":[{"version_affected":"=","version_value":"2.7.2"}]}}]},"vendor_name":"Contemporary Controls"}]}},"credits":[{"lang":"en","value":"isZzzzz (VulDB User)"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability classified as critical has been found in Contemporary Controls BASrouter BACnet BASRT-B 2.7.2. Affected is an unknown function of the component Device-Communication-Control Service. The manipulation with the input 55ff0500370015f30104025506110afb7519035d0841e4bece257b6acfc71f leads to denial of service. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-262224. NOTE: The vendor was contacted early about this disclosure but did not respond in any way."},{"lang":"deu","value":"Es wurde eine kritische Schwachstelle in Contemporary Controls BASrouter BACnet BASRT-B 2.7.2 entdeckt. Betroffen hiervon ist ein unbekannter Ablauf der Komponente Device-Communication-Control Service. Mittels Manipulieren mit der Eingabe 55ff0500370015f30104025506110afb7519035d0841e4bece257b6acfc71f mit unbekannten Daten kann eine denial of service-Schwachstelle ausgenutzt werden. Der Exploit steht zur öffentlichen Verfügung."}]},"impact":{"cvss":[{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.0"},{"baseScore":6.1,"vectorString":"AV:A/AC:L/Au:N/C:N/I:N/A:C","version":"2.0"}]},"problemtype":{"problemtype_data":[{"description":[{"cweId":"CWE-404","lang":"eng","value":"CWE-404 Denial of Service"}]}]},"references":{"reference_data":[{"name":"https://vuldb.com/?id.262224","refsource":"MISC","url":"https://vuldb.com/?id.262224"},{"name":"https://vuldb.com/?ctiid.262224","refsource":"MISC","url":"https://vuldb.com/?ctiid.262224"},{"name":"https://vuldb.com/?submit.320749","refsource":"MISC","url":"https://vuldb.com/?submit.320749"},{"name":"https://github.com/isZzzz/BASRT-B_BACnet_Router_Document/blob/main/BASRT_CVE_apply.pdf","refsource":"MISC","url":"https://github.com/isZzzz/BASRT-B_BACnet_Router_Document/blob/main/BASRT_CVE_apply.pdf"},{"name":"https://github.com/isZzzz/BASRT-B_BACnet_Router_Document/blob/main/BASER-B_backdoor.pcapng","refsource":"MISC","url":"https://github.com/isZzzz/BASRT-B_BACnet_Router_Document/blob/main/BASER-B_backdoor.pcapng"}]}},"nvd.nist.gov":{"cve":{"descriptions":[{"lang":"en","value":"A vulnerability classified as critical has been found in Contemporary Controls BASrouter BACnet BASRT-B 2.7.2. Affected is an unknown function of the component Device-Communication-Control Service. The manipulation with the input 55ff0500370015f30104025506110afb7519035d0841e4bece257b6acfc71f leads to denial of service. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-262224. NOTE: The vendor was contacted early about this disclosure but did not respond in any way."}],"id":"CVE-2024-4292","lastModified":"2024-04-27T21:15:47.453","metrics":{"cvssMetricV2":[{"acInsufInfo":false,"baseSeverity":"MEDIUM","cvssData":{"accessComplexity":"LOW","accessVector":"ADJACENT_NETWORK","authentication":"NONE","availabilityImpact":"COMPLETE","baseScore":6.1,"confidentialityImpact":"NONE","integrityImpact":"NONE","vectorString":"AV:A/AC:L/Au:N/C:N/I:N/A:C","version":"2.0"},"exploitabilityScore":6.5,"impactScore":6.9,"obtainAllPrivilege":false,"obtainOtherPrivilege":false,"obtainUserPrivilege":false,"source":"cna@vuldb.com","type":"Secondary","userInteractionRequired":false}],"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"exploitabilityScore":2.8,"impactScore":3.6,"source":"cna@vuldb.com","type":"Secondary"}]},"published":"2024-04-27T21:15:47.453","references":[{"source":"cna@vuldb.com","url":"https://github.com/isZzzz/BASRT-B_BACnet_Router_Document/blob/main/BASER-B_backdoor.pcapng"},{"source":"cna@vuldb.com","url":"https://github.com/isZzzz/BASRT-B_BACnet_Router_Document/blob/main/BASRT_CVE_apply.pdf"},{"source":"cna@vuldb.com","url":"https://vuldb.com/?ctiid.262224"},{"source":"cna@vuldb.com","url":"https://vuldb.com/?id.262224"},{"source":"cna@vuldb.com","url":"https://vuldb.com/?submit.320749"}],"sourceIdentifier":"cna@vuldb.com","vulnStatus":"Received","weaknesses":[{"description":[{"lang":"en","value":"CWE-404"}],"source":"cna@vuldb.com","type":"Primary"}]}}}}