Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-37374
HistoryMay 11, 2022 - 12:00 a.m.

Unspecified Vulnerability in Siemens Desigo PXC and DXR Devices (CNVD-2022-37374)

2022-05-1100:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
siemens
desigo pxc
dxr devices
hvac
building automation
username enumeration
security vulnerability
bacnet
tra applications
equipment monitoring

EPSS

0.001

Percentile

23.8%

Desigo DXR2 controllers are programmable automation stations to support the standard control needs of end HVAC equipment and TRA (Total Room Automation) applications. the Desigo PXC3 series of automation stations can be used in buildings where functionality and flexibility are more demanding. Use Desigo room automation when multiple disciplines (HVAC, lighting, shading) are combined to form a single solution, and when a high degree of flexibility is required.The Desigo PXC4 building automation controller is designed for HVAC system control. It is a compact device with built-in IOs that can be expanded to meet your needs with additional TX-IO modules.The Desigo PXC5 is a freely programmable controller for BACnet system-level functions such as alarm routing, system-wide scheduling and trending, and equipment monitoring.Siemens Desigo PXC and DXR Devices have A security vulnerability exists that could be exploited by an attacker to perform a username enumeration attack and identify a valid username.

EPSS

0.001

Percentile

23.8%

Related for CNVD-2022-37374