CVE-2017-9946: Siemens Apogee Pxc Firmware

High severity, CVSS 7.5. EPSS: 25% chance of exploitation in the next 30 days.

A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 443/tcp) could bypass the authentication and download sensitive information from the device.

Affected products

  • Siemens Apogee Pxc Firmware: before 3.5 (fixed in 3.5)
  • Siemens Apogee Pxc Modular Firmware: before 3.5 (fixed in 3.5)
  • Siemens Talon Tc Compact Firmware: before 3.5 (fixed in 3.5)
  • Siemens Talon Tc Modular Firmware: before 3.5 (fixed in 3.5)

Published 2017-10-23. Last modified 2026-06-17.