Improper authentication in Niagara 4 Framework and Niagara AX Framework - CVE-2017-16748
Published: August 17, 2018
Vulnerability details
The vulnerability allows a local unauthenticated attacker to bypass authentication on the target system.
The vulnerability exists on Microsoft Windows Systems due to improper authentication. A local attacker can use a disabled account name and a blank password, log into the local Niagara platform and gain administrator access to the Niagara system.
Affected software
Niagara AX Framework
Facility Explorer
How to mitigate CVE-2017-16748
Update Niagara AX Framework to version 3.8.401.
Niagara AX Framework - update to 3.8.401
Facility Explorer - addressed in versions 6.6, 14.4u1, 14.6