CVE-2012-4701
Summary
| CVE | CVE-2012-4701 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-02-15 12:09:27 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Directory traversal vulnerability in Tridium Niagara AX 3.5, 3.6, and 3.7 allows remote attackers to read sensitive files, and consequently execute arbitrary code, by leveraging (1) valid credentials or (2) the guest feature. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tridium | Niagara Ax | 3.5 | All | All | All |
| Application | Tridium | Niagara Ax | 3.6 | All | All | All |
| Application | Tridium | Niagara Ax | 3.7 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 404 - File Not Found | CISA | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Broken Link, Third Party Advisory, US Government Resource |
| Niagara AX Security Patch 11-Feb-2013 | af854a3a-2127-422b-91ae-364da2661108 | www.niagara-central.com | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590616 Tridium NiagaraAX Directory Traversal Vulnerability (ICSA-13-045-01)