A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 443/tcp) could bypass the authentication and download sensitive information from the device.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Information
Published : 2017-10-23 01:29
Updated : 2022-10-28 09:15
NVD link : CVE-2017-9946
Mitre link : CVE-2017-9946
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
siemens
- apogee_pxc_bacnet_automation_controller
- apogee_pxc_bacnet_automation_controller_firmware
- talon_tc_bacnet_automation_controller_firmware
- talon_tc_bacnet_automation_controller