QID 590616

Date Published: 2021-12-09

QID 590616: Tridium NiagaraAX Directory Traversal Vulnerability (ICSA-13-045-01)

Affected products:
Tridium NiagaraAX, all versions.

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

A loss of integrity, data, and possibly physical damage can result if the software is being used to control a physical process. Another consequence might be the compromise of facility security where NiagaraAX is used for facility access control and administration. to individual organizations depends on many factors that are unique to each organization.

  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-13-045-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590616

    Software Advisories
    Advisory ID Software Component Link
    ICSA-13-045-01 URL Logo www.us-cert.gov/ics/advisories/ICSA-13-045-01