CVE-2022-45937

CVSS V2 None CVSS V3 None
Description
A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions < V3.5.5), APOGEE PXC Series (P2 Ethernet) (All versions < V2.8.20), TALON TC Series (BACnet) (All versions < V3.5.5). A low privilege authenticated attacker with network access to the integrated web server could download sensitive information from the device containing user account credentials.
Overview
  • CVE ID
  • CVE-2022-45937
  • Assigner
  • productcert@siemens.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-12-13T16:15:24
  • Last Modified Date
  • 2022-12-19T14:34:45
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:o:siemens:pxc00-e96.a_firmware:*:*:*:*:*:*:*:* 1 OR 3.5.5
cpe:2.3:h:siemens:pxc00-e96.a:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:siemens:pxc100-e96.a_firmware:*:*:*:*:*:*:*:* 1 OR 3.5.5
cpe:2.3:h:siemens:pxc100-e96.a:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:siemens:pxx-485.3_firmware:*:*:*:*:*:*:*:* 1 OR 3.5.5
cpe:2.3:h:siemens:pxx-485.3:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:siemens:pxc16.2-pe.a_firmware:*:*:*:*:*:*:*:* 1 OR 2.8.20
cpe:2.3:h:siemens:pxc16.2-pe.a:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:siemens:pxc24.2-pe.a_firmware:*:*:*:*:*:*:*:* 1 OR 2.8.20
cpe:2.3:h:siemens:pxc24.2-pe.a:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:siemens:pxc24.2-pef.a_firmware:*:*:*:*:*:*:*:* 1 OR 2.8.20
cpe:2.3:h:siemens:pxc24.2-pef.a:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:siemens:pxc24.2-per.a_firmware:*:*:*:*:*:*:*:* 1 OR 2.8.20
cpe:2.3:h:siemens:pxc24.2-per.a:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:siemens:pxc24.2-perf.a_firmware:*:*:*:*:*:*:*:* 1 OR 2.8.20
cpe:2.3:h:siemens:pxc24.2-perf.a:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:siemens:talon_tc_modular_\(bacnet\)_firmware:*:*:*:*:*:*:*:* 1 OR 3.5.5
cpe:2.3:h:siemens:talon_tc_modular_\(bacnet\):-:*:*:*:*:*:*:* 0 OR
References
History
Created Old Value New Value Data Type Notes
2022-12-13 16:18:30 Added to TrackCVE
2022-12-13 17:22:01 2022-12-13T16:15:24.893 2022-12-13T16:15:24 CVE Published Date updated
2022-12-13 17:22:01 2022-12-13T16:52:05 CVE Modified Date updated
2022-12-13 17:22:01 Received Awaiting Analysis Vulnerability Status updated
2022-12-15 16:18:07 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2022-12-15 20:14:59 Undergoing Analysis Awaiting Analysis Vulnerability Status updated
2022-12-19 11:14:48 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2022-12-19 15:14:53 2022-12-19T14:34:45 CVE Modified Date updated
2022-12-19 15:14:53 Undergoing Analysis Analyzed Vulnerability Status updated
2022-12-19 15:14:53 NVD-CWE-noinfo Weakness Enumeration new
2022-12-19 15:14:54 CPE Information updated