An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework Versions 4.4 and prior) using a disabled account name and a blank password, granting the attacker administrator access to the Niagara system.
2018-08-20T21:29:00.807
2024-11-21T03:16:53.670
Modified
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | tridium | niagara | ≤ 4.4 | Yes |
Application | tridium | niagara_ax_framework | ≤ 3.8 | Yes |