Publication Date: 2021-11-09
Last Update: 2022-05-10
Current Version: V1.3
CVSS v3.1 Base Score: 9.8

Affected Product and Versions Remediation
APOGEE MBC (PPC) (BACnet):
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
APOGEE MBC (PPC) (P2 Ethernet):
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
APOGEE MEC (PPC) (BACnet):
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
APOGEE MEC (PPC) (P2 Ethernet):
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
APOGEE PXC Compact (BACnet):
All versions < V3.5.4
Update to V3.5.4 or later version
See further recommendations from section Workarounds and Mitigations
APOGEE PXC Compact (P2 Ethernet):
All versions < V2.8.19
Update to V2.8.19 or later version
See further recommendations from section Workarounds and Mitigations
APOGEE PXC Modular (BACnet):
All versions < V3.5.4
Update to V3.5.4 or later version
See further recommendations from section Workarounds and Mitigations
APOGEE PXC Modular (P2 Ethernet):
All versions < V2.8.19
Update to V2.8.19 or later version
See further recommendations from section Workarounds and Mitigations
Desigo PXC00-E.D:
All versions >= V2.3 and < V6.30.016
Update to V6.30.016 or later version
https://support.industry.siemens.com/cs/ww/en/view/109810577
See further recommendations from section Workarounds and Mitigations
Desigo PXC00-U:
All versions >= V2.3 and < V6.30.016
Update to V6.30.016 or later version
https://support.industry.siemens.com/cs/ww/en/view/109810577
See further recommendations from section Workarounds and Mitigations
Desigo PXC001-E.D:
All versions >= V2.3 and < V6.30.016
Update to V6.30.016 or later version
https://support.industry.siemens.com/cs/ww/en/view/109810577
See further recommendations from section Workarounds and Mitigations
Desigo PXC12-E.D:
All versions >= V2.3 and < V6.30.016
Update to V6.30.016 or later version
https://support.industry.siemens.com/cs/ww/en/view/109810577
See further recommendations from section Workarounds and Mitigations
Desigo PXC22-E.D:
All versions >= V2.3 and < V6.30.016
Update to V6.30.016 or later version
https://support.industry.siemens.com/cs/ww/en/view/109810577
See further recommendations from section Workarounds and Mitigations
Desigo PXC22.1-E.D:
All versions >= V2.3 and < V6.30.016
Update to V6.30.016 or later version
https://support.industry.siemens.com/cs/ww/en/view/109810577
See further recommendations from section Workarounds and Mitigations
Desigo PXC36.1-E.D:
All versions >= V2.3 and < V6.30.016
Update to V6.30.016 or later version
https://support.industry.siemens.com/cs/ww/en/view/109810577
See further recommendations from section Workarounds and Mitigations
Desigo PXC50-E.D:
All versions >= V2.3 and < V6.30.016
Update to V6.30.016 or later version
https://support.industry.siemens.com/cs/ww/en/view/109810577
See further recommendations from section Workarounds and Mitigations
Desigo PXC64-U:
All versions >= V2.3 and < V6.30.016
Update to V6.30.016 or later version
https://support.industry.siemens.com/cs/ww/en/view/109810577
See further recommendations from section Workarounds and Mitigations
Desigo PXC100-E.D:
All versions >= V2.3 and < V6.30.016
Update to V6.30.016 or later version
https://support.industry.siemens.com/cs/ww/en/view/109810577
See further recommendations from section Workarounds and Mitigations
Desigo PXC128-U:
All versions >= V2.3 and < V6.30.016
Update to V6.30.016 or later version
https://support.industry.siemens.com/cs/ww/en/view/109810577
See further recommendations from section Workarounds and Mitigations
Desigo PXC200-E.D:
All versions >= V2.3 and < V6.30.016
Update to V6.30.016 or later version
https://support.industry.siemens.com/cs/ww/en/view/109810577
See further recommendations from section Workarounds and Mitigations
Desigo PXM20-E:
All versions >= V2.3 and < V6.30.016
Update to V6.30.016 or later version
https://support.industry.siemens.com/cs/ww/en/view/109810577
See further recommendations from section Workarounds and Mitigations
TALON TC Compact (BACnet):
All versions < V3.5.4
Update to V3.5.4 or later version
See further recommendations from section Workarounds and Mitigations
TALON TC Modular (BACnet):
All versions < V3.5.4
Update to V3.5.4 or later version
See further recommendations from section Workarounds and Mitigations

CVSS v3.1 Base Score 5.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
CWE: CWE-843: Access of Resource Using Incompatible Type (‘Type Confusion’)

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
CWE: CWE-1284: Improper Validation of Specified Quantity in Input

CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-1284: Improper Validation of Specified Quantity in Input

CVSS v3.1 Base Score 7.1
CVSS Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-125: Out-of-bounds Read

CVSS v3.1 Base Score 6.5
CVSS Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

CVSS v3.1 Base Score 7.1
CVSS Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

CVSS v3.1 Base Score 8.8
CVSS Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-170: Improper Null Termination

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
CWE: CWE-805: Buffer Access with Incorrect Length Value

CVSS v3.1 Base Score 9.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-170: Improper Null Termination

CVSS v3.1 Base Score 8.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-170: Improper Null Termination

CVSS v3.1 Base Score 8.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-170: Improper Null Termination

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-191: Integer Underflow (Wrap or Wraparound)

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-240: Improper Handling of Inconsistent Structural Elements

https://www.siemens.com/cert/advisories