CVSS2
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:A/AC:L/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
ADJACENT
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
AI Score
Confidence
High
EPSS
Percentile
23.4%
A timeout during a TLS handshake can result in the connection failing to terminate. This can result in a Niagara thread hanging and requires a manual restart of Niagara (Versions 4.6.96.28, 4.7.109.20, 4.7.110.32, 4.8.0.110) and Niagara Enterprise Security (Versions 2.4.31, 2.4.45, 4.8.0.35) to correct.
Vendor | Product | Version | CPE |
---|---|---|---|
tridium | niagara | 4.6.96.28 | cpe:2.3:a:tridium:niagara:4.6.96.28:*:*:*:*:*:*:* |
tridium | niagara | 4.7.109.20 | cpe:2.3:a:tridium:niagara:4.7.109.20:*:*:*:*:*:*:* |
tridium | niagara | 4.7.110.32 | cpe:2.3:a:tridium:niagara:4.7.110.32:*:*:*:*:*:*:* |
tridium | niagara | 4.8.0.110 | cpe:2.3:a:tridium:niagara:4.8.0.110:*:*:*:*:*:*:* |
tridium | niagara_enterprise_security | 2.4.31 | cpe:2.3:a:tridium:niagara_enterprise_security:2.4.31:*:*:*:*:*:*:* |
tridium | niagara_enterprise_security | 2.4.45 | cpe:2.3:a:tridium:niagara_enterprise_security:2.4.45:*:*:*:*:*:*:* |
tridium | niagara_enterprise_security | 4.8.0.35 | cpe:2.3:a:tridium:niagara_enterprise_security:4.8.0.35:*:*:*:*:*:*:* |
CVSS2
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:A/AC:L/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
ADJACENT
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
AI Score
Confidence
High
EPSS
Percentile
23.4%