CVE-2017-16744: Path Traversal
A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior installed on Microsoft Windows Systems can be exploited by leveraging valid platform (administrator) credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16744?
The severity of CVE-2017-16744 is critical due to its ability to allow unauthorized access to sensitive files through path traversal.
How do I fix CVE-2017-16744?
To fix CVE-2017-16744, upgrade Tridium Niagara AX to versions later than 3.8 or Niagara 4 to versions later than 4.4.
What systems are affected by CVE-2017-16744?
CVE-2017-16744 affects Tridium Niagara AX versions 3.8 and prior, as well as Niagara 4 systems versions 4.4 and prior installed on Microsoft Windows.
What exploitation methods exist for CVE-2017-16744?
CVE-2017-16744 can be exploited by leveraging valid platform (administrator) credentials to perform path traversal attacks.
Is there a workaround for CVE-2017-16744?
Currently, the recommended response for CVE-2017-16744 is to apply the updates as there are no effective workarounds to mitigate the vulnerability.