Medium severity5.3NVD Advisory· Published Oct 23, 2017· Updated May 13, 2026
CVE-2017-9947
CVE-2017-9947
Description
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server (80/tcp and 443/tcp) to obtain information on the structure of the file system of the affected devices.
Affected products
4- cpe:2.3:o:siemens:apogee_pxc_firmware:*:*:*:*:*:*:*:*Range: <3.5
- cpe:2.3:o:siemens:apogee_pxc_modular_firmware:*:*:*:*:*:*:*:*Range: <3.5
- cpe:2.3:o:siemens:talon_tc_compact_firmware:*:*:*:*:*:*:*:*Range: <3.5
- cpe:2.3:o:siemens:talon_tc_modular_firmware:*:*:*:*:*:*:*:*Range: <3.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- packetstormsecurity.com/files/169544/Siemens-APOGEE-PXC-TALON-TC-Authentication-Bypass.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/101248nvdBroken LinkThird Party AdvisoryVDB Entry
- cert-portal.siemens.com/productcert/pdf/ssa-148078.pdfnvdVendor Advisory
- www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-148078.pdfnvdBroken LinkVendor Advisory
News mentions
0No linked articles in our index yet.