#VU14443 Improper authentication in Niagara 4 Framework and Niagara AX Framework - CVE-2017-16748
Published: August 17, 2018
Niagara 4 Framework
Niagara AX Framework
Tridium
Description
The vulnerability allows a local unauthenticated attacker to bypass authentication on the target system.
The vulnerability exists on Microsoft Windows Systems due to improper authentication. A local attacker can use a disabled account name and a blank password, log into the local Niagara platform and gain administrator access to the Niagara system.
Remediation
Update Niagara AX Framework to version 3.8.401.