PT-2012-4445 · Tridium · Tridium Niagara Ax Framework

Publicado

2012-08-16

·

Atualizado

2023-03-22

·

CVE-2012-3024

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Tridium Niagara AX Framework versions prior to 3.8 is not mentioned, however, it is mentioned that versions through 3.6 are affected. Therefore: Tridium Niagara AX Framework versions through 3.6
Description The issue is related to the use of predictable values for session IDs and keys, which could allow remote attackers to bypass authentication through a brute-force attack.
Recommendations For Tridium Niagara AX Framework versions through 3.6, consider implementing additional authentication measures to prevent brute-force attacks, such as account lockout policies or IP blocking, until a fixed version is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-3024

Produtos afetados

Tridium Niagara Ax Framework