CVE-2017-9946 is an authentication bypass vulnerability affecting Siemens APOGEE PXC and TALON TC BACnet Automation Controllers (all versions <V3.5). An unauthenticated attacker with network access to the integrated web server (ports 80/tcp and 443/tcp) could exploit this flaw to download sensitive information from the device. Rated 7.5 HIGH on CVSS, this vulnerability has a low attack complexity and high confidentiality impact, but no integrity or availability impact. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.5CPE matchmatch criteria | cpe:2.3:o:siemens:apogee_pxc_firmware:*:*:*:*:*:*:*:* | ||
< 3.5CPE matchmatch criteria | cpe:2.3:o:siemens:apogee_pxc_modular_firmware:*:*:*:*:*:*:*:* | ||
< 3.5CPE matchmatch criteria | cpe:2.3:o:siemens:talon_tc_compact_firmware:*:*:*:*:*:*:*:* | ||
< 3.5CPE matchmatch criteria | cpe:2.3:o:siemens:talon_tc_modular_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.