High severity7.5NVD Advisory· Published Oct 23, 2017· Updated Jun 17, 2026
CVE-2017-9946
CVE-2017-9946
Description
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 443/tcp) could bypass the authentication and download sensitive information from the device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:o:siemens:apogee_pxc_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:siemens:apogee_pxc_firmware:*:*:*:*:*:*:*:*range: <3.5
- cpe:2.3:o:siemens:apogee_pxc_modular_firmware:*:*:*:*:*:*:*:*range: <3.5
- cpe:2.3:o:siemens:talon_tc_compact_firmware:*:*:*:*:*:*:*:*Range: <3.5
- cpe:2.3:o:siemens:talon_tc_modular_firmware:*:*:*:*:*:*:*:*Range: <3.5
- Range: <V3.5
- Range: <V3.5
Patches
Vulnerability mechanics
References
5- packetstormsecurity.com/files/169544/Siemens-APOGEE-PXC-TALON-TC-Authentication-Bypass.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/101248nvdBroken LinkThird Party AdvisoryVDB Entry
- cert-portal.siemens.com/productcert/pdf/ssa-148078.pdfnvdVendor Advisory
- www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-148078.pdfnvdBroken LinkVendor Advisory
- packetstorm.news/files/id/169544nvd
News mentions
0No linked articles in our index yet.