File Access Vulnerability in Niagara AX and Niagara 4 Products by Tridium
CVE-2019-13528

4.4MEDIUM

Key Information:

Vendor

Tridium

Status
Vendor
CVE Published:
24 September 2019

What is CVE-2019-13528?

A vulnerability exists in certain versions of Tridium's Niagara AX and Niagara 4 systems that may allow an attacker to gain unauthorized read access to sensitive and privileged files. This issue affects specific JACE models and can potentially expose critical system information that should remain confidential.

Affected Version(s)

Niagara Niagara AX 3.8u4 (JACE 3e, JACE 6e, JACE 7, JACE-8000), Niagara 4.4u3 (JACE 3e, JACE 6e, JACE 7, JACE-8000), Niagara 4.7u1 (JACE-8000, Edge 10)

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.