Unrestricted Access Vulnerability in Siemens APOGEE and TALON TC Series Products
CVE-2025-40757

6.3MEDIUM

What is CVE-2025-40757?

A vulnerability has been discovered in Siemens APOGEE PXC Series and TALON TC Series products that permits unrestricted access to sensitive files over the network. Devices that are connected can expose encrypted database files, including those containing passwords, to unauthorized users. This raises significant security risks, as attackers could exploit this weakness to gain access to confidential information and compromise system integrity.

Affected Version(s)

APOGEE PXC Series (BACnet) 0

APOGEE PXC Series (P2 Ethernet) 0

TALON TC Series (BACnet) 0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.