Tridium Niagara Framework
cpe:2.3:a:tridium:niagara:*:*:*:*:*:*:*
- < 4.14.2
- < 4.15.1
- < 4.10.11
A vulnerability allowing parameter injection has been identified in the Tridium Niagara Framework and Niagara Enterprise Security. This issue arises from the use of the GET request method with sensitive query strings, creating opportunities for parameter injection attacks. The vulnerability is present in several versions of the Niagara Framework and Niagara Enterprise Security, prior to specific patched releases.
Exploitation of this vulnerability could lead to unauthorized parameter injection, potentially allowing attackers to manipulate application behavior or data.
Users are advised to upgrade to Tridium Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.