Tridium Niagara Framework
cpe:2.3:a:tridium:niagara:*:*:*:*:*:*:*
- < 4.14.2
- < 4.15.1
- < 4.10.11
A vulnerability allowing cryptanalysis through observable response discrepancies has been identified in the Tridium Niagara Framework and Niagara Enterprise Security. This issue affects multiple versions prior to the latest releases, specifically versions before 4.14.2, 4.15.1, and 4.10.11. The vulnerability is present on various operating systems, including Windows, Linux, and QNX.
Exploitation of this vulnerability could lead to cryptographic weaknesses, potentially allowing an attacker to decipher encrypted information or manipulate cryptographic processes.
Users are advised to upgrade to Tridium Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.