CVE-2022-38371 - CVE House
Back to Database
Status published High CVE-2022-38371

A vulnerability has been identified in APOGEE MBC (PPC) (BACnet)...

Vulnerability Description

A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.7), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.21), APOGEE PXC Modular (BACnet) (All versions < V3.5.7), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.21), Desigo PXC00-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC00-U (All versions >= V2.3 < V6.30.37), Desigo PXC001-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC100-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC12-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC128-U (All versions >= V2.3 < V6.30.37), Desigo PXC200-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC22-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC22.1-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC36.1-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC50-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC64-U (All versions >= V2.3 < V6.30.37), Desigo PXM20-E (All versions >= V2.3 < V6.30.37), Nucleus NET for Nucleus PLUS V1 (All versions < V5.2a), Nucleus NET for Nucleus PLUS V2 (All versions < V5.4), Nucleus ReadyStart V3 V2012 (All versions < V2012.08.1), Nucleus ReadyStart V3 V2017 (All versions < V2017.02.4), Nucleus Source Code (All versions including affected FTP server), TALON TC Compact (BACnet) (All versions < V3.5.7), TALON TC Modular (BACnet) (All versions < V3.5.7). The FTP server does not properly release memory resources that were reserved for incomplete connection attempts by FTP clients. This could allow a remote attacker to generate a denial of service condition on devices that incorporate a vulnerable version of the FTP server.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-38371

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

APOGEE MBC (PPC) (BACnet), APOGEE MBC (PPC) (P2 Ethernet), APOGEE MEC (PPC) (BACnet), APOGEE MEC (PPC) (P2 Ethernet), APOGEE PXC Compact (BACnet), APOGEE PXC Compact (P2 Ethernet), APOGEE PXC Modular (BACnet), APOGEE PXC Modular (P2 Ethernet), Desigo PXC00-E.D, Desigo PXC00-U, Desigo PXC001-E.D, Desigo PXC100-E.D, Desigo PXC12-E.D, Desigo PXC128-U, Desigo PXC200-E.D, Desigo PXC22-E.D, Desigo PXC22.1-E.D, Desigo PXC36.1-E.D, Desigo PXC50-E.D, Desigo PXC64-U, Desigo PXM20-E, Nucleus NET for Nucleus PLUS V1, Nucleus NET for Nucleus PLUS V2, Nucleus ReadyStart V3 V2012, Nucleus ReadyStart V3 V2017, Nucleus Source Code, TALON TC Compact (BACnet), TALON TC Modular (BACnet)
Vulnerable Versions:
All versions, 0, V2.3, All versions < V5.2a, All versions < V5.4, All versions < V2012.08.1, All versions < V2017.02.4

Timeline

Official Publish: October 11th, 2022
Last Modified: May 13th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)