Tridium Niagara Framework
cpe:2.3:a:tridium:niagara:*:*:*:*:*:*:*
- < 4.14.2
- < 4.15.1
- < 4.10.11
A vulnerability exists in the Tridium Niagara Framework and Niagara Enterprise Security, all prior to certain versions, due to the use of password hashes that require insufficient computational effort. This weakness allows for cryptanalysis, potentially compromising password security.
Exploitation of this vulnerability could lead to successful cryptographic attacks, allowing an adversary to recover passwords or password equivalents, thereby gaining unauthorized access to user accounts or systems.
Users are advised to upgrade to Tridium Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.