A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 443/tcp) could bypass the authentication and download sensitive information from the device.
References
| Link | Resource |
|---|---|
| https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-148078.pdf | Vendor Advisory |
| http://www.securityfocus.com/bid/101248 | Third Party Advisory VDB Entry |
| https://cert-portal.siemens.com/productcert/pdf/ssa-148078.pdf |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Information
Published : 2017-10-23 08:29
Updated : 2022-06-14 11:15
NVD link : CVE-2017-9946
Mitre link : CVE-2017-9946
JSON object : View
Products Affected
siemens
- apogee_pxc_bacnet_automation_controller
- apogee_pxc_bacnet_automation_controller_firmware
- talon_tc_bacnet_automation_controller
- talon_tc_bacnet_automation_controller_firmware
CWE
CWE-287
Improper Authentication
