Monday, 28 July, 2025
Critical Flaws in Tridium’s Niagara Framework Enable Root‑Level Takeover of Building Automation Systems

Cybersecurity researchers at Nozomi Networks Labs uncovered 13 critical vulnerabilities spanning nine CVEs in Tridium’s widely used Niagara Framework (versions 4.10u10, 4.14u1 and earlier). Flaws like improper password hashing (CVE‑2025‑3937), incorrect permissions and argument injection can be chained—especially over unencrypted Syslog—to achieve root‑level remote code execution and full system compromise. Tridium has released patches and urges immediate updates and network segmentation.
Read full story at The Hacker News