CVE-2017-9947: Path Traversal
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server (80/tcp and 443/tcp) to obtain information on the structure of the file system of the affected devices.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9947?
CVE-2017-9947 is considered a critical vulnerability that can be exploited by remote attackers.
How do I fix CVE-2017-9947?
To fix CVE-2017-9947, upgrade the affected Siemens APOGEE PXC and TALON TC controllers to firmware version 3.5 or later.
What does CVE-2017-9947 affect?
CVE-2017-9947 affects Siemens APOGEE PXC and TALON TC BACnet Automation Controllers with versions prior to 3.5.
Can CVE-2017-9947 be exploited remotely?
Yes, CVE-2017-9947 can be exploited remotely by an attacker with network access to the affected integrated web server.
What type of vulnerability is CVE-2017-9947?
CVE-2017-9947 is a directory traversal vulnerability that allows unauthorized access to information on the web server.