Niagara

Vendor:

First CVE: Aug 20, 2018 · Active for 7 years

14
Total CVEs
More Total CVEs than 91% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Niagara over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 2018
7 years ago
Most Recent CVE
May 22, 2025
429 days ago

CVE Severity & Scoring

Niagara14 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (7.1%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (92.9%)
Unknown0 (0.0%)
Required1 (7.1%)
Privileges Required
Low1 (7.1%)
High1 (7.1%)
None12 (85.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework Versions 4.4 and prior) using a disabled account name and a
Aug 20, 20189.833NONO
Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This
May 22, 20259.829NONO
Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Exploiting Incorr
May 22, 20259.829NONO
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX all
May 22, 20259.827NONO
Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This i
May 22, 20259.827NONO
Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Ma
May 22, 20259.827NONO
Use of Password Hash With Insufficient Computational Effort vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux
May 22, 20259.827NONO
A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior installed on Microsoft Windows Systems can be exploited by
Aug 20, 20187.227NONO
Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data
May 22, 20259.825NONO
Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX
May 22, 20257.523NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Niagara

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.8.0.11014.30.4%00
4.7.110.3214.30.4%00
4.7.109.2014.30.4%00
4.6.96.2814.30.4%00
4.4u215.41.0%00
4.15108.91.1%00
4.14u1108.91.1%00
4.10u10108.91.1%00