Weak Encryption Vulnerability in APOGEE PXC and TALON TC Series by Siemens
CVE-2024-54089
8.7HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 11 February 2025
Summary
A critical vulnerability exists in various models of Siemens APOGEE PXC and TALON TC Series devices due to a weak encryption scheme relying on a hard-coded key. This vulnerability enables attackers to potentially deduce or decrypt sensitive passwords from intercepted cyphertext, thereby compromising the security of affected systems. Organizations using these devices should assess their infrastructure and implement necessary safeguards to mitigate potential threats stemming from this weakness.
Affected Version(s)
APOGEE PXC Series (BACnet) 0
APOGEE PXC Series (P2 Ethernet) 0
TALON TC Series (BACnet) 0
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved