CVE-2022-45937
published 2022-12-13CVE-2022-45937: A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.61%
45.4th percentile
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). A low privilege authenticated attacker with network access to the integrated web server could download sensitive information from the device containing user account credentials.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | apogee_pxc_compact | — | — |
| siemens | apogee_pxc_compact | — | — |
| siemens | apogee_pxc_modular | — | — |
| siemens | apogee_pxc_modular | — | — |
| siemens | pxc00-e96.a_firmware | < 3.5.5 | 3.5.5 |
| siemens | pxc100-e96.a_firmware | < 3.5.5 | 3.5.5 |
| siemens | pxc16.2-pe.a_firmware | < 2.8.20 | 2.8.20 |
| siemens | pxc24.2-pe.a_firmware | < 2.8.20 | 2.8.20 |
| siemens | pxc24.2-pef.a_firmware | < 2.8.20 | 2.8.20 |
| siemens | pxc24.2-per.a_firmware | < 2.8.20 | 2.8.20 |
| siemens | pxc24.2-perf.a_firmware | < 2.8.20 | 2.8.20 |
| siemens | pxx-485.3_firmware | < 3.5.5 | 3.5.5 |
| siemens | talon_tc_compact | — | — |
| siemens | talon_tc_modular | — | — |
| siemens | talon_tc_modular_firmware | < 3.5.5 | 3.5.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p69w-f9ww-g922: A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions < V3
ghsa_unreviewed·2022-12-13
CVE-2022-45937 [MEDIUM] CWE-284 GHSA-p69w-f9ww-g922: A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions < V3
A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions < V3.5.5), APOGEE PXC Series (P2 Ethernet) (All versions < V2.8.20), TALON TC Series (BACnet) (All versions < V3.5.5). A low privilege authenticated attacker with network access to the integrated web server could download sensitive information from the device containing user account credentials.
CISA ICS
Siemens APOGEE and TALON
cisa_ics·2022-12-15·CVSS 8.8
[HIGH] Siemens APOGEE and TALON
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens APOGEE and TALON
Last RevisedDecember 15, 2022
Alert CodeICSA-22-349-16
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: APOGEE and TALON
- Vulnerability: Improper Access Control
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow a low privilege authenticated attacker to gain high privilege access.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Siemens APOGEE PXC and TALON TC Series, a building automation and control systems, are a
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-13
Published