PT-2012-4445 · Tridium · Tridium Niagara Ax Framework

Published

2012-08-16

·

Updated

2023-03-22

·

CVE-2012-3024

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Tridium Niagara AX Framework versions prior to 3.8 is not mentioned, however, it is mentioned that versions through 3.6 are affected. Therefore: Tridium Niagara AX Framework versions through 3.6
Description The issue is related to the use of predictable values for session IDs and keys, which could allow remote attackers to bypass authentication through a brute-force attack.
Recommendations For Tridium Niagara AX Framework versions through 3.6, consider implementing additional authentication measures to prevent brute-force attacks, such as account lockout policies or IP blocking, until a fixed version is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3024

Affected Products

Tridium Niagara Ax Framework