Niagara
Tridium · 14 CVEs
Improper Neutralization of Argument Delimiters in a Command (‘Argument Injection’)
May 22, 2025
Incorrect Permission Assignment for Critical Resource
May 22, 2025
Use of GET Request Method With sensitive Query Strings
May 22, 2025
Improper Output Neutralization for Logs
May 22, 2025
Improper Handling of Windows: DATA Alternate Data Stream
May 22, 2025
Improper Use of Validation Framework
May 22, 2025
Observable Response Discrepancy
May 22, 2025
Missing Cryptographic Step
May 22, 2025
Use of Password Hash with Insufficient Computational Effort
May 22, 2025
Incorrect Permission Assignment for Critical Resource
May 22, 2025
A timeout during a TLS handshake can result in the connection failing to terminate. This can result in a Niagara thread…
Aug 13, 2020
Tridium Niagara Enterprise Security 2.3u1, all versions prior to 2.3.118.6, Niagara AX 3.8u4, all versions prior to 3.8…
Jan 29, 2019
An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework…
Aug 20, 2018
A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prio…
Aug 20, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-3945 | Improper Neutralization of Argument Delimiters in a Command (‘Argument Injection’) | CRITICAL | 0.65% | May 22, 2025 |
| CVE-2025-3944 | Incorrect Permission Assignment for Critical Resource | CRITICAL | 0.53% | May 22, 2025 |
| CVE-2025-3943 | Use of GET Request Method With sensitive Query Strings | HIGH | 10.68% | May 22, 2025 |
| CVE-2025-3942 | Improper Output Neutralization for Logs | HIGH | 0.29% | May 22, 2025 |
| CVE-2025-3941 | Improper Handling of Windows: DATA Alternate Data Stream | CRITICAL | 0.53% | May 22, 2025 |
| CVE-2025-3940 | Improper Use of Validation Framework | CRITICAL | 0.36% | May 22, 2025 |
| CVE-2025-3939 | Observable Response Discrepancy | MEDIUM | 0.32% | May 22, 2025 |
| CVE-2025-3938 | Missing Cryptographic Step | CRITICAL | 0.35% | May 22, 2025 |
| CVE-2025-3937 | Use of Password Hash with Insufficient Computational Effort | CRITICAL | 0.36% | May 22, 2025 |
| CVE-2025-3936 | Incorrect Permission Assignment for Critical Resource | CRITICAL | 0.39% | May 22, 2025 |
| CVE-2020-14483 | A timeout during a TLS handshake can result in the connection failing to terminate. This can result in a Niagara thread hanging and requires a manual restart o… | MEDIUM | 0.42% | Aug 13, 2020 |
| CVE-2018-18985 | Tridium Niagara Enterprise Security 2.3u1, all versions prior to 2.3.118.6, Niagara AX 3.8u4, all versions prior to 3.8.401.1, Niagara 4.4u2, all versions prio… | MEDIUM | 0.97% | Jan 29, 2019 |
| CVE-2017-16748 | An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework Versions 4.4 and prior) using a disable… | CRITICAL | 5.29% | Aug 20, 2018 |
| CVE-2017-16744 | A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior installed on Microsoft Windows Systems… | HIGH | 6.22% | Aug 20, 2018 |
Showing 1 to 14 of 14 CVEs