TLS Handshake Timeout Vulnerability in Niagara and Niagara Enterprise Security by Tridium
CVE-2020-14483
4.3MEDIUM
What is CVE-2020-14483?
A timeout issue during the TLS handshake process in Tridium’s Niagara and Niagara Enterprise Security can cause the connection to fail without proper termination. This failure results in Niagara threads becoming unresponsive, necessitating a manual restart of the affected Niagara services to restore functionality. Versions impacted include specific releases of Niagara and Niagara Enterprise Security, emphasizing the need for timely updates to mitigate potential operational disruptions.
Affected Version(s)
Niagara Niagara: Versions 4.6.96.28, 4.7.109.20, 4.7.110.32, 4.8.0.110 and Niagara Enterprise Security: Versions 2.4.31, 2.4.45, 4.8.0.35
