CyberRota Analysis
AI-GeneratedA vulnerability exists in the handling of dynamically created BACnet File Objects, allowing an unauthenticated remote attacker to exploit insufficient validation of file paths. This can lead to directory traversal, enabling the attacker to read or overwrite arbitrary files on the device, potentially resulting in full system compromise. Organizations utilizing BACnet-enabled devices should prioritize patching this critical vulnerability to mitigate the risk of unauthorized access and data manipulation.
Original NVD Description
The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.