CVE-2017-9947

A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server (80/tcp and 443/tcp) to obtain information on the structure of the file system of the affected devices.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:apogee_pxc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:apogee_pxc:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:apogee_pxc_modular_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:apogee_pxc_modular:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:talon_tc_compact_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:talon_tc_compact:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:talon_tc_modular_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:talon_tc_modular:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:37

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/169544/Siemens-APOGEE-PXC-TALON-TC-Authentication-Bypass.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/169544/Siemens-APOGEE-PXC-TALON-TC-Authentication-Bypass.html - Exploit, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/101248 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/101248 - Broken Link, Third Party Advisory, VDB Entry
References () https://cert-portal.siemens.com/productcert/pdf/ssa-148078.pdf - Vendor Advisory () https://cert-portal.siemens.com/productcert/pdf/ssa-148078.pdf - Vendor Advisory
References () https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-148078.pdf - Broken Link, Vendor Advisory () https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-148078.pdf - Broken Link, Vendor Advisory

09 May 2023, 16:27

Type Values Removed Values Added
References (MISC) http://packetstormsecurity.com/files/169544/Siemens-APOGEE-PXC-TALON-TC-Authentication-Bypass.html - (MISC) http://packetstormsecurity.com/files/169544/Siemens-APOGEE-PXC-TALON-TC-Authentication-Bypass.html - Exploit, Third Party Advisory, VDB Entry
References (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-148078.pdf - (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-148078.pdf - Vendor Advisory
References (BID) http://www.securityfocus.com/bid/101248 - Third Party Advisory, VDB Entry (BID) http://www.securityfocus.com/bid/101248 - Broken Link, Third Party Advisory, VDB Entry
References (CONFIRM) https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-148078.pdf - Vendor Advisory (CONFIRM) https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-148078.pdf - Broken Link, Vendor Advisory
First Time Siemens talon Tc Modular Firmware
Siemens apogee Pxc Modular
Siemens talon Tc Modular
Siemens talon Tc Compact Firmware
Siemens apogee Pxc Modular Firmware
Siemens talon Tc Compact
Siemens apogee Pxc
Siemens apogee Pxc Firmware
CPE cpe:2.3:o:siemens:apogee_pxc_bacnet_automation_controller_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:apogee_pxc_bacnet_automation_controller:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:talon_tc_bacnet_automation_controller:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:apogee_pxc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:talon_tc_compact_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:apogee_pxc_modular_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:apogee_pxc:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:talon_tc_compact:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:talon_tc_modular:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:apogee_pxc_modular:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:talon_tc_modular_firmware:*:*:*:*:*:*:*:*

Information

Published : 2017-10-23 08:29

Updated : 2025-04-20 01:37


NVD link : CVE-2017-9947

Mitre link : CVE-2017-9947

CVE.ORG link : CVE-2017-9947


JSON object : View

Products Affected

siemens

  • apogee_pxc_modular
  • talon_tc_modular
  • apogee_pxc_firmware
  • talon_tc_compact
  • talon_tc_compact_firmware
  • talon_tc_modular_firmware
  • apogee_pxc_modular_firmware
  • apogee_pxc
CWE
CWE-538

Insertion of Sensitive Information into Externally-Accessible File or Directory

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')