CVE-2017-9947 is a directory traversal vulnerability affecting Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions prior to V3.5. A remote attacker with network access to the integrated web server can exploit this flaw to gain information about the device's file system structure. This vulnerability has a CVSS score of 5.3 (Medium), indicating a low-complexity attack that requires no privileges or user interaction, resulting in a low impact on confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the CISA KEV catalog, though it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.5CPE matchmatch criteria | cpe:2.3:o:siemens:apogee_pxc_firmware:*:*:*:*:*:*:*:* | ||
< 3.5CPE matchmatch criteria | cpe:2.3:o:siemens:apogee_pxc_modular_firmware:*:*:*:*:*:*:*:* | ||
< 3.5CPE matchmatch criteria | cpe:2.3:o:siemens:talon_tc_compact_firmware:*:*:*:*:*:*:*:* | ||
< 3.5CPE matchmatch criteria | cpe:2.3:o:siemens:talon_tc_modular_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.