The vendor explicitly identifies these products as affected by this CVE.
- APOGEE PXC Compact (BACnet)
- APOGEE PXC Compact (P2 Ethernet)
- APOGEE PXC Modular (BACnet)
- APOGEE PXC Modular (P2 Ethernet)
- TALON TC Compact (BACnet)
- TALON TC Modular (BACnet)
- Summary
- The DNS domain name record decompression functionality does not properly validate the pointer offset values. The parsing of malformed responses could result in a write past the end of an allocated structure. An attacker with a privileged position in the network could leverage this vulnerability to execute code in the context of the current process or cause a denial-of-service condition.
- Remediation
- Update to V2.8.20 or later version
