CVE-2017-16748

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
20/08/2018
Last modified:
03/04/2019

Description

An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework Versions 4.4 and prior) using a disabled account name and a blank password, granting the attacker administrator access to the Niagara system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tridium:niagara:*:*:*:*:*:*:*:* 4.4 (including)
cpe:2.3:a:tridium:niagara_ax_framework:*:*:*:*:*:*:*:* 3.8 (including)