Tridium Niagara Framework and Enterprise Security Missing Cryptographic Step Vulnerability Allowing Cryptanalysis

Vulnerability

A vulnerability exists in the Tridium Niagara Framework and Niagara Enterprise Security due to a missing cryptographic step, which allows for cryptanalysis. This issue is present in several versions prior to the latest updates. Tridium recommends users upgrade to specific patched versions.

Impact

Exploitation of this vulnerability could lead to cryptanalysis, potentially allowing attackers to decipher encrypted information or manipulate cryptographic processes.

Remediation

Users are advised to upgrade to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.