ZeroHour

CVE-2017-9947

PoC
CVSS 3.1
5.3 medium
EPSS
7%p94
Published
()
Modified
Description

A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server (80/tcp and 443/tcp) to obtain information on the structure of the file system of the affected devices.

Vendors
siemens
Products
apogee pxc firmware, apogee pxc modular firmware, talon tc compact firmware, talon tc modular firmware
Weakness
CWE-538, CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news