logo

Multiple Vulnerabilities in Tridium Niagara Framework Let Attacker to Collect Sensitive Data from the Network

ID: ce6fe1d8-a31f-5f13-bf8b-a3bbb8f85d34

STIX ID: report--ce6fe1d8-a31f-5f13-bf8b-a3bbb8f85d34

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2025-07-25

Date Updated: 2026-04-21

Author: Florence

...
...

Researchers disclosed multiple critical vulnerabilities in Tridium's Niagara Framework (consolidated into ten CVEs) that can enable privilege escalation and root remote code execution, particularly when network encryption is disabled and Syslog is unencrypted. The report details an attack chain using intercepted GET anti-CSRF tokens and JSESSIONID extraction from unencrypted Syslog, highlights high CVSS scores (up to 7.7), and urges immediate patching, network segmentation, and configuration changes to protect building automation and other critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.