# CVE-2025-40555

## Summary

- **CVE ID:** CVE-2025-40555
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L)
- **CWE:** CWE-440
- **Published:** May 13, 2025
- **Last Modified:** Mar 12, 2026

## Description

A vulnerability has been identified in APOGEE PXC+TALON TC Series (BACnet) (All versions). Affected devices start sending unsolicited BACnet broadcast messages after processing a specific BACnet createObject request. This could allow an attacker residing in the same BACnet network to send a specially crafted message that results in a partial denial of service condition of the targeted device, and potentially reduce the availability of BACnet network. A power cycle is required to restore the device's normal operation.

## Affected Products

- Siemens — APOGEE PXC+TALON TC Series (BACnet) (0)

## References

- [CNA](https://cert-portal.siemens.com/productcert/html/ssa-718393.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 11.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._