Tridium / Niagara
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-3945 | Improper Neutralization of Argument Delimiters in a Command (‘Argument Injection’) | CRITICAL | 9.8 | May 22, 2025 |
| CVE-2025-3944 | Incorrect Permission Assignment for Critical Resource | CRITICAL | 9.8 | May 22, 2025 |
| CVE-2025-3943 | Use of GET Request Method With sensitive Query Strings | HIGH | 7.5 | May 22, 2025 |
| CVE-2025-3942 | Improper Output Neutralization for Logs | HIGH | 7.5 | May 22, 2025 |
| CVE-2025-3941 | Improper Handling of Windows: DATA Alternate Data Stream | CRITICAL | 9.8 | May 22, 2025 |
| CVE-2025-3940 | Improper Use of Validation Framework | CRITICAL | 9.8 | May 22, 2025 |
| CVE-2025-3939 | Observable Response Discrepancy | MEDIUM | 5.3 | May 22, 2025 |
| CVE-2025-3938 | Missing Cryptographic Step | CRITICAL | 9.8 | May 22, 2025 |
| CVE-2025-3937 | Use of Password Hash with Insufficient Computational Effort | CRITICAL | 9.8 | May 22, 2025 |
| CVE-2025-3936 | Incorrect Permission Assignment for Critical Resource | CRITICAL | 9.8 | May 22, 2025 |
| CVE-2020-14483 | A timeout during a TLS handshake can result in the connection failing to terminate. This can result in a Niagara thread hanging and requires a manual restart o… | MEDIUM | 4.3 | Aug 13, 2020 |
| CVE-2018-18985 | Tridium Niagara Enterprise Security 2.3u1, all versions prior to 2.3.118.6, Niagara AX 3.8u4, all versions prior to 3.8.401.1, Niagara 4.4u2, all versions prio… | MEDIUM | 5.4 | Jan 29, 2019 |
| CVE-2017-16748 | An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework Versions 4.4 and prior) using a disable… | CRITICAL | 9.8 | Aug 20, 2018 |
| CVE-2017-16744 | A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior installed on Microsoft Windows Systems… | HIGH | 7.2 | Aug 20, 2018 |
Showing 1 to 14 of 14 CVEs