CVE-2022-45937
Summary
| CVE | CVE-2022-45937 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-13 16:15:00 UTC |
| Updated | 2023-08-08 10:15:00 UTC |
| Description | A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). A low privilege authenticated attacker with network access to the integrated web server could download sensitive information from the device containing user account credentials. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Siemens | Pxc00-e96.a | - | All | All | All |
| Operating System | Siemens | Pxc00-e96.a Firmware | All | All | All | All |
| Hardware | Siemens | Pxc100-e96.a | - | All | All | All |
| Operating System | Siemens | Pxc100-e96.a Firmware | All | All | All | All |
| Hardware | Siemens | Pxc16.2-pe.a | - | All | All | All |
| Operating System | Siemens | Pxc16.2-pe.a Firmware | All | All | All | All |
| Hardware | Siemens | Pxc24.2-pe.a | - | All | All | All |
| Operating System | Siemens | Pxc24.2-pe.a Firmware | All | All | All | All |
| Hardware | Siemens | Pxc24.2-pef.a | - | All | All | All |
| Operating System | Siemens | Pxc24.2-pef.a Firmware | All | All | All | All |
| Hardware | Siemens | Pxc24.2-per.a | - | All | All | All |
| Operating System | Siemens | Pxc24.2-per.a Firmware | All | All | All | All |
| Hardware | Siemens | Pxc24.2-perf.a | - | All | All | All |
| Operating System | Siemens | Pxc24.2-perf.a Firmware | All | All | All | All |
| Hardware | Siemens | Pxx-485.3 | - | All | All | All |
| Operating System | Siemens | Pxx-485.3 Firmware | All | All | All | All |
| Hardware | Siemens | Talon Tc Modular Bacnet | - | All | All | All |
| Operating System | Siemens | Talon Tc Modular Bacnet Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| N/A | CONFIRM | cert-portal.siemens.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591273 Siemens APOGEE and TALON Improper Access Control Vulnerability (ICSA-22-349-16, SSA-180579)