CVE-2017-9947: Siemens Apogee Pxc Firmware

Medium severity, CVSS 5.3. EPSS: 7.3% chance of exploitation in the next 30 days.

A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server (80/tcp and 443/tcp) to obtain information on the structure of the file system of the affected devices.

Affected products

  • Siemens Apogee Pxc Firmware: before 3.5 (fixed in 3.5)
  • Siemens Apogee Pxc Modular Firmware: before 3.5 (fixed in 3.5)
  • Siemens Talon Tc Compact Firmware: before 3.5 (fixed in 3.5)
  • Siemens Talon Tc Modular Firmware: before 3.5 (fixed in 3.5)

Published 2017-10-23. Last modified 2026-06-17.