Severity
8.7HIGH
EPSS
0.8%
top 26.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11

Description

A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions = V2.3 = V2.3 = V2.3 = V2.3 = V2.3 = V2.3 = V2.3 = V2.3 = V2.3 = V2.3 = V2.3 = V2.3 = V2.3 < V6.30.37), Nucleus NET for Nucleus PLUS V1 (All versions < V5.2a), Nucleus NET for Nucleus PLUS V2 (All versions < V5.4), Nucleus ReadyStart V3 V201

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Packages41 packages

CVEListV5siemens/nucleus_readystart_v3_v2012All versions < V2012.08.1
CVEListV5siemens/nucleus_readystart_v3_v2017All versions < V2017.02.4
CVEListV5siemens/apogee_mbc_(ppc)_(bacnet)All versions

Patches

🔴Vulnerability Details

2
GHSA
GHSA-59qg-qcpj-8hf9: A vulnerability has been identified in Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions), Nucleus Source Code (Versions including affec2022-10-11
CVEList
CVE-2022-38371: A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACn2022-10-11
CVE-2022-38371 (HIGH CVSS 8.7) | A vulnerability has been identified | cvebase.io