CVE-2019-13528 is a vulnerability in specific Tridium Niagara AX and Niagara 4 products (JACE 3e, 6e, 7, 8000, and Edge 10) that allows an attacker to gain read access to privileged files. With a CVSS score of 4.4 (Medium), this vulnerability requires high privileges (PR:H) and local access (AV:L) to exploit, but does not require user interaction (UI:N). While it has a low EPSS score and is not listed in KEV, indicating a low likelihood of active exploitation, it has garnered some community discussion and media coverage. There is currently no public exploit code available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.8u4CPE matchmatch criteria | cpe:2.3:o:tridium:niagara_ax:3.8u4:*:*:*:*:*:*:* | ||
4.4u3CPE matchmatch criteria | cpe:2.3:o:tridium:niagara4:4.4u3:*:*:*:*:*:*:* | ||
4.7u1CPE matchmatch criteria | cpe:2.3:o:tridium:niagara4:4.7u1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.