VulnerabilityModified
CVE-2012-3024
Tridium Niagara AX Framework through 3.6 uses predictable values for (1) session IDs and (2) keys, which might allow remote attackers to bypass authentication via a brute-force attack.
MEDIUM 5.0EPSS 2.20%
Does this matter?
Lower severity and a low EPSS score (2.20%). Track it; it rarely justifies an emergency change on its own.
Description
Tridium Niagara AX Framework through 3.6 uses predictable values for (1) session IDs and (2) keys, which might allow remote attackers to bypass authentication via a brute-force attack.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.20% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- tridium/niagara ax
- Source
- ics-cert@hq.dhs.gov
References
- http://www.tridium.com/cs/tridium_news/security_patch_36Broken Link, Patch, Vendor Advisory
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-228-01.pdfBroken Link, Third Party Advisory, US Government Resource
- http://www.tridium.com/cs/tridium_news/security_patch_36Broken Link, Patch, Vendor Advisory
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-228-01.pdfBroken Link, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.