QID 590915

Date Published: 2022-07-18

QID 590915: Siemens BACnet Field Panels (Update A) Multiple Vulnerabilities (ICSA-17-285-05) (ssa-148078)

AFFECTED PRODUCTS
Siemens reports that the vulnerabilities affect the following BACnet field panels:
APOGEE PXC Compact (BACnet): All versions prior to v3.5
APOGEE PXC Compact (P2 Ethernet): All versions
APOGEE PXC Modular (BACnet): All versions prior to v3.5
APOGEE PXC Modular (P2 Ethernet): All versions
TALON TC Compact (BACnet): All versions prior to v3.5
TALON TC Modular (BACnet): All versions prior to v3.5

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities could allow unauthenticated attackers with access to the integrated webserver to download sensitive information.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-17-285-05 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590915

    Software Advisories
    Advisory ID Software Component Link
    ICSA-17-285-05 URL Logo www.us-cert.gov/ics/advisories/ICSA-17-285-05
    ssa-148078 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-148078.pdf