CVE-2012-3024: Medium severity tridium niagara vulnerability
Published Aug 16, 2012
·Updated
Tridium Niagara AX Framework through 3.6 uses predictable values for (1) session IDs and (2) keys, which might allow remote attackers to bypass authentication via a brute-force attack.
Affected Software
1 affected component
Tridium Niagara AX<=3.6
Remediation
Patch Available
Event History
Aug 16, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3024?
CVE-2012-3024 has a medium severity rating, indicating a significant risk due to predictable session IDs and keys.
2
How do I fix CVE-2012-3024?
To mitigate CVE-2012-3024, upgrade to a version of Tridium Niagara AX later than 3.6 that addresses this vulnerability.
3
What vulnerabilities are associated with CVE-2012-3024?
CVE-2012-3024 specifically allows attackers to bypass authentication through predictable session IDs and keys.
4
Who is affected by CVE-2012-3024?
Users of Tridium Niagara AX Framework versions up to and including 3.6 are affected by CVE-2012-3024.
5
Can CVE-2012-3024 be exploited remotely?
Yes, CVE-2012-3024 can be exploited remotely, allowing unauthorized access through brute-force attacks.