Under certain conditions, an attacker could bind to the same port used
by WebCTRL. This could allow the attacker to craft and send malicious
packets and impersonate the WebCTRL service without requiring code
injection into the WebCTRL software.
For users of supported versions of WebCTRL (WebCTRL 8.5
cumulative releases and later), Automated Logic provides secure
configuration guidance for hardware and software deployments; BACnet
Secure Connect (BACnet/SC) support, which introduces TLS encryption and
mutual authentication; and published best practices for network
segmentation, access control, and secure protocol implementation.
Additional information is available at:
https://www.automatedlogic.com/en/company/security-commitment/