VulnerabilityModified
CVE-2012-4027
Directory traversal vulnerability in Tridium Niagara AX Framework allows remote attackers to read files outside of the intended images, nav, and px folders by leveraging incorrect permissions, as demonstrated by reading the config.bog file.
MEDIUM 5.0EPSS 2.54%
Does this matter?
Lower severity and a low EPSS score (2.54%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Tridium Niagara AX Framework allows remote attackers to read files outside of the intended images, nav, and px folders by leveraging incorrect permissions, as demonstrated by reading the config.bog file.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.54% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- tridium/niagara ax
- Source
- cve@mitre.org
References
- http://www.washingtonpost.com/investigations/tridiums-niagara-framework-marvel-of-connectivity-illustrates-new-cyber-risks/2012/07/11/gJQARJL6dW_story.htmlPermissions Required
- https://www.tridium.com/galleries/briefings/NiagaraAX_Framework_Software_Security_Alert.pdfBroken Link, Vendor Advisory
- http://www.washingtonpost.com/investigations/tridiums-niagara-framework-marvel-of-connectivity-illustrates-new-cyber-risks/2012/07/11/gJQARJL6dW_story.htmlPermissions Required
- https://www.tridium.com/galleries/briefings/NiagaraAX_Framework_Software_Security_Alert.pdfBroken Link, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.