ZeroHour

CVE-2017-9946

PoC
CVSS 3.1
7.5 high
EPSS
25%p98
Published
()
Modified
Description

A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 443/tcp) could bypass the authentication and download sensitive information from the device.

Vendors
siemens
Products
apogee pxc firmware, apogee pxc modular firmware, talon tc compact firmware, talon tc modular firmware
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news