CVE-2017-9946
HIGHSiemens APOGEE PXC & TALON TC <V3.5 - Authentication Bypass via Web Server
Title source: llmDescription
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 443/tcp) could bypass the authentication and download sensitive information from the device.
References (4)
Core 4
Core References
Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/169544/Siemens-APOGEE-PXC-TALON-TC-Authentication-Bypass.html
Vendor Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-148078.pdf
Broken Link, Vendor Advisory
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-148078.pdf
Broken Link, Third Party Advisory, VDB Entry vdb-entry
http://www.securityfocus.com/bid/101248
Scores
CVSS v3
7.5
EPSS
0.0055
EPSS Percentile
68.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-287
Status
published
Products (5)
n/a/APOGEE PXC and TALON TC BACnet Automation Controllers All versions <V3.5
APOGEE PXC and TALON TC BACnet Automation Controllers All versions <V3.5
siemens/apogee_pxc_firmware
< 3.5
siemens/apogee_pxc_modular_firmware
< 3.5
siemens/talon_tc_compact_firmware
< 3.5
siemens/talon_tc_modular_firmware
< 3.5
Published
Oct 23, 2017
Tracked Since
Feb 18, 2026