QID 591292

Date Published: 2023-01-20

QID 591292: Siemens APOGEE/TALON Field Panels Predictable Exact Value from Previous Values Vulnerability (ICSA-22-349-10, SSA-436469)

AFFECTED PRODUCTS
APOGEE PXC Series (BACnet): All versions prior to 3.5.5
APOGEE PXC Series (P2 Ethernet): All versions prior to 2.8.20
TALON TC Series (BACnet): All versions prior to 3.5.5

QID Detection Logic:
This QID checks for the Vulnerable version of Siemens APOGEE/TALON Field Panels using passive scanning.

Successful exploitation of this vulnerability could allow an attacker to hijack existing sessions or spoof future sessions.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-349-10 or Siemens MITIGATIONS section SSA-436469 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591292

    Software Advisories
    Advisory ID Software Component Link
    ICSA-22-349-10 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-349-10
    SSA-436469 URL Logo cert-portal.siemens.com/productcert/html/ssa-436469.html