Authentication Bypass in Tridium Niagara AX Framework
CVE-2012-3024

Currently unrated

Key Information:

Vendor

Tridium

Vendor
CVE Published:
16 August 2012

What is CVE-2012-3024?

The Tridium Niagara AX Framework version 3.6 is vulnerable due to the use of predictable values for session IDs and encryption keys. This allows remote attackers to employ brute-force methods to bypass authentication mechanisms, potentially leading to unauthorized access to sensitive system controls and data.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.