CVE-2022-45937: High severity siemens pxc00-e96.a vulnerability

Published Dec 13, 2022
·
Updated

A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). A low privilege authenticated attacker with network access to the integrated web server could download sensitive information from the device containing user account credentials.

Affected Software

36 affected components
Siemens Pxc00-e96.a Firmware<3.5.5
Siemens Pxc00-e96.a
Siemens Pxc100-e96.a Firmware<3.5.5
Siemens Pxc100-e96.a
Siemens Pxx-485.3 Firmware<3.5.5
Siemens Pxx-485.3
Siemens Pxc16.2-pe.a Firmware<2.8.20
Siemens Pxc16.2-pe.a
Siemens Pxc24.2-pe.a Firmware<2.8.20
Siemens Pxc24.2-pe.a
Siemens Pxc24.2-pef.a Firmware<2.8.20
Siemens Pxc24.2-pef.a
Siemens Pxc24.2-per.a Firmware<2.8.20
Siemens Pxc24.2-per.a
Siemens Pxc24.2-perf.a Firmware<2.8.20
Siemens Pxc24.2-perf.a
Siemens Talon Tc Modular \(bacnet\) Firmware<3.5.5
Siemens Talon Tc Modular \(bacnet\)
All of the following
Siemens Pxc00-e96.a Firmware<3.5.5
Siemens Pxc00-e96.a
All of the following
Siemens Pxc100-e96.a Firmware<3.5.5
Siemens Pxc100-e96.a
All of the following
Siemens Pxx-485.3 Firmware<3.5.5
Siemens Pxx-485.3
All of the following
Siemens Pxc16.2-pe.a Firmware<2.8.20
Siemens Pxc16.2-pe.a
All of the following
Siemens Pxc24.2-pe.a Firmware<2.8.20
Siemens Pxc24.2-pe.a
All of the following
Siemens Pxc24.2-pef.a Firmware<2.8.20
Siemens Pxc24.2-pef.a
All of the following
Siemens Pxc24.2-per.a Firmware<2.8.20
Siemens Pxc24.2-per.a
All of the following
Siemens Pxc24.2-perf.a Firmware<2.8.20
Siemens Pxc24.2-perf.a
All of the following
Siemens Talon Tc Modular \(bacnet\) Firmware<3.5.5
Siemens Talon Tc Modular \(bacnet\)

Event History

Dec 13, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-45937?

CVE-2022-45937 has been classified as a moderate severity vulnerability.

2

How do I fix CVE-2022-45937?

To fix CVE-2022-45937, upgrade to the latest versions of affected software as specified by Siemens.

3

Which versions are affected by CVE-2022-45937?

CVE-2022-45937 affects all versions of certain Siemens firmware below specified versions including APOGEE PXC Compact, Modular, and TALON TC products.

4

What are the potential impacts of exploiting CVE-2022-45937?

Exploiting CVE-2022-45937 could allow unauthorized access and manipulation of the vulnerable systems.

5

Is there a patch for CVE-2022-45937?

Yes, Siemens has released patches to address CVE-2022-45937 which should be applied immediately.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203