Multiple Vulnerabilities in Tridium Niagara Framework Let Attacker to Collect Sensitive Data from the Network
ID: ce6fe1d8-a31f-5f13-bf8b-a3bbb8f85d34
STIX ID: report--ce6fe1d8-a31f-5f13-bf8b-a3bbb8f85d34
Feed Name: cybersecurityNews.com
Researchers disclosed multiple critical vulnerabilities in Tridium's Niagara Framework (consolidated into ten CVEs) that can enable privilege escalation and root remote code execution, particularly when network encryption is disabled and Syslog is unencrypted. The report details an attack chain using intercepted GET anti-CSRF tokens and JSESSIONID extraction from unencrypted Syslog, highlights high CVSS scores (up to 7.7), and urges immediate patching, network segmentation, and configuration changes to protect building automation and other critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
