CVE-2017-16748: Critical severity tridium niagara framework vulnerability
An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework Versions 4.4 and prior) using a disabled account name and a blank password, granting the attacker administrator access to the Niagara system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16748?
CVE-2017-16748 has a high severity rating due to the potential for unauthorized administrative access.
How do I fix CVE-2017-16748?
To fix CVE-2017-16748, ensure that all user accounts that should not have access are disabled and implement strong password policies.
How does CVE-2017-16748 affect my system?
CVE-2017-16748 allows an attacker to gain administrator access through a disabled account with a blank password, compromising system security.
Which versions are affected by CVE-2017-16748?
CVE-2017-16748 affects Niagara AX Framework Versions 3.8 and prior, and Niagara 4 Framework Versions 4.4 and prior.
What types of systems are impacted by CVE-2017-16748?
CVE-2017-16748 impacts systems utilizing the Tridium Niagara platforms, which are commonly used in building automation controls.