A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server (80/tcp and 443/tcp) to obtain information on the structure of the file system of the affected devices.
References
Link | Resource |
---|---|
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-148078.pdf | Broken Link Vendor Advisory |
http://www.securityfocus.com/bid/101248 | Broken Link Third Party Advisory VDB Entry |
https://cert-portal.siemens.com/productcert/pdf/ssa-148078.pdf | Vendor Advisory |
http://packetstormsecurity.com/files/169544/Siemens-APOGEE-PXC-TALON-TC-Authentication-Bypass.html | Exploit Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
09 May 2023, 16:27
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:siemens:apogee_pxc_bacnet_automation_controller:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:talon_tc_bacnet_automation_controller:-:*:*:*:*:*:*:* |
cpe:2.3:h:siemens:talon_tc_modular:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:talon_tc_compact:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:talon_tc_compact_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:apogee_pxc_modular_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:apogee_pxc_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:talon_tc_modular_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:siemens:apogee_pxc:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:apogee_pxc_modular:-:*:*:*:*:*:*:* |
First Time |
Siemens talon Tc Compact Firmware
Siemens apogee Pxc Modular Firmware Siemens apogee Pxc Firmware Siemens apogee Pxc Modular Siemens apogee Pxc Siemens talon Tc Modular Siemens talon Tc Compact Siemens talon Tc Modular Firmware |
|
References | (MISC) http://packetstormsecurity.com/files/169544/Siemens-APOGEE-PXC-TALON-TC-Authentication-Bypass.html - Exploit, Third Party Advisory, VDB Entry | |
References | (CONFIRM) https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-148078.pdf - Broken Link, Vendor Advisory | |
References | (BID) http://www.securityfocus.com/bid/101248 - Broken Link, Third Party Advisory, VDB Entry | |
References | (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-148078.pdf - Vendor Advisory |
Information
Published : 2017-10-23 08:29
Updated : 2023-05-09 16:27
NVD link : CVE-2017-9947
Mitre link : CVE-2017-9947
JSON object : View
Products Affected
siemens
- apogee_pxc_modular_firmware
- apogee_pxc_modular
- talon_tc_compact
- talon_tc_modular
- talon_tc_modular_firmware
- apogee_pxc_firmware
- talon_tc_compact_firmware
- apogee_pxc
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')