Authentication bypass in BACnet Field Panels - CVE-2017-9946

 

Authentication bypass in BACnet Field Panels - CVE-2017-9946

Published: October 13, 2017


Vulnerability identifier: #VU8819
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9946
CWE-ID: CWE-288
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The weakness exists due to authentication bypass. A remote attacker with network access to the integrated web server (Ports 80/TCP and 443/TCP) can bypass authentication and download information from the device.

Affected software

BACnet Field Panels
TALON TC Modular (BACnet)
TALON TC Compact (BACnet)
APOGEE PXC Modular (BACnet)
APOGEE PXC Compact (BACnet)

How to mitigate CVE-2017-9946

Update to version 3.5.

TALON TC Modular (BACnet) - update to 3.5
TALON TC Compact (BACnet) - update to 3.5
APOGEE PXC Modular (BACnet) - update to 3.5
APOGEE PXC Compact (BACnet) - update to 3.5

External References

Related Security Bulletins