{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2017-9947","assignerOrgId":"cec7a2ec-15b4-4faf-bd53-b40f371f3a77","assignerShortName":"siemens","dateUpdated":"2024-08-05T17:25:00.484Z","dateReserved":"2017-06-26T00:00:00.000Z","datePublished":"2017-10-23T00:00:00.000Z"},"containers":{"cna":{"providerMetadata":{"orgId":"cec7a2ec-15b4-4faf-bd53-b40f371f3a77","shortName":"siemens","dateUpdated":"2022-10-28T00:00:00.000Z"},"descriptions":[{"lang":"en","value":"A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server (80/tcp and 443/tcp) to obtain information on the structure of the file system of the affected devices."}],"affected":[{"vendor":"n/a","product":"APOGEE PXC and TALON TC BACnet Automation Controllers All versions <V3.5","versions":[{"version":"APOGEE PXC and TALON TC BACnet Automation Controllers All versions <V3.5","status":"affected"}]}],"references":[{"name":"101248","tags":["vdb-entry"],"url":"http://www.securityfocus.com/bid/101248"},{"url":"https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-148078.pdf"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-148078.pdf"},{"url":"http://packetstormsecurity.com/files/169544/Siemens-APOGEE-PXC-TALON-TC-Authentication-Bypass.html"}],"problemTypes":[{"descriptions":[{"type":"CWE","lang":"en","description":"CWE-538: File and Directory Information Exposure","cweId":"CWE-538"}]}],"datePublic":"2017-10-23T00:00:00.000Z"},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-05T17:25:00.484Z"},"title":"CVE Program Container","references":[{"name":"101248","tags":["vdb-entry","x_transferred"],"url":"http://www.securityfocus.com/bid/101248"},{"url":"https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-148078.pdf","tags":["x_transferred"]},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-148078.pdf","tags":["x_transferred"]},{"url":"http://packetstormsecurity.com/files/169544/Siemens-APOGEE-PXC-TALON-TC-Authentication-Bypass.html","tags":["x_transferred"]}]}]}}