Thursday, 11 September

Monday, 28 July2025

Critical Flaws in Tridium’s Niagara Framework Enable Root‑Level Takeover of Building Automation Systems

Critical Flaws in Tridium’s Niagara Framework Enable Root‑Level Takeover of Building Automation Systems
Cybersecurity researchers at Nozomi Networks Labs uncovered 13 critical vulnerabilities spanning nine CVEs in Tridiums widely used Niagara Framework (versions 4.10u10, 4.14u1 and earlier). Flaws like improper password hashing (CVE20253937), incorrect permissions and argument injection can be chainedespecially over unencrypted Syslogto achieve rootlevel remote code execution and full system compromise. Tridium has released patches and urges immediate updates and network segmentation.

Subscribe To Our Newsletter.

Full Name
Email