{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2017-9946","assignerOrgId":"cec7a2ec-15b4-4faf-bd53-b40f371f3a77","assignerShortName":"siemens","dateUpdated":"2024-08-05T17:25:00.381Z","dateReserved":"2017-06-26T00:00:00.000Z","datePublished":"2017-10-23T00:00:00.000Z"},"containers":{"cna":{"providerMetadata":{"orgId":"cec7a2ec-15b4-4faf-bd53-b40f371f3a77","shortName":"siemens","dateUpdated":"2022-10-28T00:00:00.000Z"},"descriptions":[{"lang":"en","value":"A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 443/tcp) could bypass the authentication and download sensitive information from the device."}],"affected":[{"vendor":"n/a","product":"APOGEE PXC and TALON TC BACnet Automation Controllers All versions <V3.5","versions":[{"version":"APOGEE PXC and TALON TC BACnet Automation Controllers All versions <V3.5","status":"affected"}]}],"references":[{"name":"101248","tags":["vdb-entry"],"url":"http://www.securityfocus.com/bid/101248"},{"url":"https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-148078.pdf"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-148078.pdf"},{"url":"http://packetstormsecurity.com/files/169544/Siemens-APOGEE-PXC-TALON-TC-Authentication-Bypass.html"}],"problemTypes":[{"descriptions":[{"type":"CWE","lang":"en","description":"CWE-287: Improper Authentication","cweId":"CWE-287"}]}],"datePublic":"2017-10-23T00:00:00.000Z"},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-05T17:25:00.381Z"},"title":"CVE Program Container","references":[{"name":"101248","tags":["vdb-entry","x_transferred"],"url":"http://www.securityfocus.com/bid/101248"},{"url":"https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-148078.pdf","tags":["x_transferred"]},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-148078.pdf","tags":["x_transferred"]},{"url":"http://packetstormsecurity.com/files/169544/Siemens-APOGEE-PXC-TALON-TC-Authentication-Bypass.html","tags":["x_transferred"]}]}]}}