A vulnerability has been identified in APOGEE PXC+TALON TC Series (BACnet) (All versions). Affected devices start sending unsolicited BACnet broadcast messages after processing a specific BACnet createObject request. This could allow an attacker residing in the same BACnet network to send a specially crafted message that results in a partial denial of service condition of the targeted device, and potentially reduce the availability of BACnet network. A power cycle is required to restore the device's normal operation.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 13 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 13 May 2025 09:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A vulnerability has been identified in APOGEE PXC+TALON TC Series (BACnet) (All versions). Affected devices start sending unsolicited BACnet broadcast messages after processing a specific BACnet createObject request. This could allow an attacker residing in the same BACnet network to send a specially crafted message that results in a partial denial of service condition of the targeted device, and potentially reduce the availability of BACnet network. A power cycle is required to restore the device's normal operation. | |
| Weaknesses | CWE-440 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
 
  | 
Status: PUBLISHED
Assigner: siemens
Published: 2025-05-13T09:38:50.440Z
Updated: 2025-05-13T13:25:06.076Z
Reserved: 2025-04-16T08:20:17.029Z
Link: CVE-2025-40555
Updated: 2025-05-13T13:25:01.590Z
Status : Awaiting Analysis
Published: 2025-05-13T10:15:25.790
Modified: 2025-05-13T19:35:18.080
Link: CVE-2025-40555
No data.