Multiple Siemens Products Authentication Bypass and Directory Traversal Vulnerabilities
BID:101248
Info
Multiple Siemens Products Authentication Bypass and Directory Traversal Vulnerabilities
| Bugtraq ID: | 101248 |
| Class: | Design Error |
| CVE: |
CVE-2017-9946 CVE-2017-9947 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2017 12:00AM |
| Updated: | Oct 12 2017 12:00AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Siemens TALON TC BACnet Automation Controllers 3.4 Siemens APOGEE PXC BACnet Automation Controllers 3.4 |
| Not Vulnerable: |
Siemens TALON TC BACnet Automation Controllers 3.5 Siemens APOGEE PXC BACnet Automation Controllers 3.5 |
Discussion
Multiple Siemens Products Authentication Bypass and Directory Traversal Vulnerabilities
Multiple Siemens Products are prone to an authentication-bypass and directory-traversal vulnerabilities.
Attackers may exploit these issues to gain unauthorized access to restricted content by bypassing intended security restrictions or to obtain sensitive information that may aid in launching further attacks.
The following products are affected:
Siemens APOGEE PXC BACnet Automation Controllers versions prior to 3.5.
Siemens TALON TC BACnet Automation Controllers versions prior to 3.5.
Multiple Siemens Products are prone to an authentication-bypass and directory-traversal vulnerabilities.
Attackers may exploit these issues to gain unauthorized access to restricted content by bypassing intended security restrictions or to obtain sensitive information that may aid in launching further attacks.
The following products are affected:
Siemens APOGEE PXC BACnet Automation Controllers versions prior to 3.5.
Siemens TALON TC BACnet Automation Controllers versions prior to 3.5.
Exploit / POC
Multiple Siemens Products Authentication Bypass and Directory Traversal Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].