Tridium Niagara Framework and Enterprise Security Observable Response Discrepancy Vulnerability Allowing Cryptanalysis

Vulnerability

A vulnerability allowing cryptanalysis through observable response discrepancies has been identified in the Tridium Niagara Framework and Niagara Enterprise Security. This issue affects multiple versions prior to the latest releases, specifically versions before 4.14.2, 4.15.1, and 4.10.11. The vulnerability is present on various operating systems, including Windows, Linux, and QNX.

Impact

Exploitation of this vulnerability could lead to cryptographic weaknesses, potentially allowing an attacker to decipher encrypted information or manipulate cryptographic processes.

Remediation

Users are advised to upgrade to Tridium Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
0.6
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.