A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server (80/tcp and 443/tcp) to obtain information on the structure of the file system of the affected devices.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Information
Published : 2017-10-23 01:29
Updated : 2022-10-28 09:15
NVD link : CVE-2017-9947
Mitre link : CVE-2017-9947
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
siemens
- apogee_pxc_bacnet_automation_controller
- apogee_pxc_bacnet_automation_controller_firmware
- talon_tc_bacnet_automation_controller