A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server (80/tcp and 443/tcp) to obtain information on the structure of the file system of the affected devices.
2017-10-23T08:29:00.867
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | siemens | apogee_pxc_firmware | < 3.5 | Yes |
Hardware | siemens | apogee_pxc | - | No |
Operating System | siemens | apogee_pxc_modular_firmware | < 3.5 | Yes |
Hardware | siemens | apogee_pxc_modular | - | No |
Operating System | siemens | talon_tc_compact_firmware | < 3.5 | Yes |
Hardware | siemens | talon_tc_compact | - | No |
Operating System | siemens | talon_tc_modular_firmware | < 3.5 | Yes |
Hardware | siemens | talon_tc_modular | - | No |