ID

VAR-201305-0369


TITLE

TRIDIUM NiagaraAX has an unknown vulnerability

Trust: 0.6

sources: CNVD: CNVD-2013-05965

DESCRIPTION

TRIDIUM NiagaraAX is an automated framework technology in a software framework, open modular platform. TRIDIUM NiagaraAX has an unidentified security vulnerability that allows remote attackers to exploit vulnerabilities. TRIDIUM NiagaraAX is prone to an unspecified vulnerability. Little is known about this issue or its effects at this time. We will update this BID as more information emerges

Trust: 0.99

sources: CNVD: CNVD-2013-05965 // BID: 59945 // IVD: fb31aad6-1f22-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: fb31aad6-1f22-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-05965

AFFECTED PRODUCTS

vendor:tridiummodel:niagara axscope: - version: -

Trust: 0.6

vendor:tridiummodel:niagaraaxscope:eqversion:0

Trust: 0.3

vendor:tridiummodel:niagara axscope:eqversion:*

Trust: 0.2

sources: IVD: fb31aad6-1f22-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-05965 // BID: 59945

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-05965
value: HIGH

Trust: 0.6

IVD: fb31aad6-1f22-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

CNVD: CNVD-2013-05965
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: fb31aad6-1f22-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: fb31aad6-1f22-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-05965

THREAT TYPE

network

Trust: 0.3

sources: BID: 59945

TYPE

Unknown

Trust: 0.3

sources: BID: 59945

EXTERNAL IDS

db:BIDid:59945

Trust: 0.9

db:CNVDid:CNVD-2013-05965

Trust: 0.8

db:IVDid:FB31AAD6-1F22-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: fb31aad6-1f22-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-05965 // BID: 59945

REFERENCES

url:http://cylance.com/techblog/googles-buildings-hackable.shtml

Trust: 0.9

url:http://www.niagaraax.com/

Trust: 0.3

sources: CNVD: CNVD-2013-05965 // BID: 59945

CREDITS

Billy Rios of Cylance Inc.

Trust: 0.3

sources: BID: 59945

SOURCES

db:IVDid:fb31aad6-1f22-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2013-05965
db:BIDid:59945

LAST UPDATE DATE

2022-05-17T01:46:36.279000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-05965date:2013-05-27T00:00:00
db:BIDid:59945date:2013-05-16T00:00:00

SOURCES RELEASE DATE

db:IVDid:fb31aad6-1f22-11e6-abef-000c29c66e3ddate:2013-05-23T00:00:00
db:CNVDid:CNVD-2013-05965date:2013-05-23T00:00:00
db:BIDid:59945date:2013-05-16T00:00:00