CVE-2022-45937: High severity siemens pxc00-e96.a vulnerability
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). A low privilege authenticated attacker with network access to the integrated web server could download sensitive information from the device containing user account credentials.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45937?
CVE-2022-45937 has been classified as a moderate severity vulnerability.
How do I fix CVE-2022-45937?
To fix CVE-2022-45937, upgrade to the latest versions of affected software as specified by Siemens.
Which versions are affected by CVE-2022-45937?
CVE-2022-45937 affects all versions of certain Siemens firmware below specified versions including APOGEE PXC Compact, Modular, and TALON TC products.
What are the potential impacts of exploiting CVE-2022-45937?
Exploiting CVE-2022-45937 could allow unauthorized access and manipulation of the vulnerable systems.
Is there a patch for CVE-2022-45937?
Yes, Siemens has released patches to address CVE-2022-45937 which should be applied immediately.