Skip to main content

Vendor archive

tridium CVEs

Beta · best-effort

20 CVEs tagged to vendor tridium2 Critical, 5 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2012-4701

Published Feb 15, 2013

Directory traversal vulnerability in Tridium Niagara AX 3.5, 3.6, and 3.7 allows remote attackers to read sensitive files, and consequently execute arbitrary code, by leveraging (…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-3025

Published Aug 16, 2012

The default configuration of Tridium Niagara AX Framework through 3.6 uses a cleartext base64 format for transmission of credentials in cookies, which allows remote attackers to o…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3024

Published Aug 16, 2012

Tridium Niagara AX Framework through 3.6 uses predictable values for (1) session IDs and (2) keys, which might allow remote attackers to bypass authentication via a brute-force at…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4028

Published Jul 16, 2012

Tridium Niagara AX Framework does not properly store credential data, which allows context-dependent attackers to bypass intended access restrictions by using the stored informati…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4027

Published Jul 16, 2012

Directory traversal vulnerability in Tridium Niagara AX Framework allows remote attackers to read files outside of the intended images, nav, and px folders by leveraging incorrect…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1