Directory Traversal Vulnerability in Siemens Automation Controllers
CVE-2017-9947
5.3MEDIUM
What is CVE-2017-9947?
A directory traversal flaw has been found in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers that allows a remote attacker with network access to the device's integrated web server to exploit the vulnerability. By leveraging this flaw, an attacker could retrieve sensitive information regarding the internal file system structure of the affected devices, potentially leading to further exploitation or unauthorized access.
Affected Version(s)
APOGEE PXC and TALON TC BACnet Automation Controllers All <V3.5 APOGEE PXC and TALON TC BACnet Automation Controllers All versions <V3.5
References
EPSS Score
30% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved