CVE-2025-40555
A vulnerability has been identified in APOGEE PXC+TALON TC Series (BACnet) (All versions). Affected devices start sending unsolicited BACnet broadcast messages after processing a specific BACnet createObject request. This could allow an attacker residing in the same BACnet network to send a specially crafted message that results in a partial denial of service condition of the targeted device, and potentially reduce the availability of BACnet network. A power cycle is required to restore the device's normal operation.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
- EPSS probability
- 0.21%
- CWE
- CWE-440
- Published
- 2025-05-13
- Last modified
- 2026-03-12
Affected products
- Siemens APOGEE PXC+TALON TC Series (BACnet)
Weakness type
Related vulnerabilities
- CVE-2026-16769 — RS9116W/SiWx917 plaintext pause encryption request causes DOS
- CVE-2026-65934 — BT122 plaintext pause encryption request causes DOS
- CVE-2026-65932 — BT122 stops advertising
- CVE-2026-8806 — Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET/IP Ethernet module
- CVE-2026-42752 — WordPress Stripe Payments plugin <= 2.0.98 - Bypass Vulnerability vulnerability
- CVE-2026-49316 — Indian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft shutdown
- CVE-2026-42534 — Jostle logic bypass degrades resolution performance
- CVE-2026-41136 — free5GC AMF missing default case in Content-Type switch in HTTPUEContextTransfer