CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-54090: A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series...

5.9 CVSS

Description

A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain an out-of-bounds read in the memory dump function.
This could allow an attacker with Medium (MED) or higher privileges to cause the device to enter an insecure cold start state.

Classification

CVE ID: CVE-2024-54090

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.9

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

Vendor: Siemens

Product: APOGEE PXC Series (BACnet)

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 19.88% (scored less or equal to compared to others)

EPSS Date: 2025-03-12 (when was this score calculated)

References

https://cert-portal.siemens.com/productcert/html/ssa-615116.html

Timeline