Description
Improper Output Neutralization for Logs vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Problem types
CWE-117 Improper Output Neutralization for Logs
Product status
Any version before 4.14.2
Any version before 4.15.1
Any version before 4.10.11
Any version before 4.14.2
Any version before 4.15.1
Any version before 4.10.11
Credits
Andrea Palanca and team at Nozomi Networks
References
www.tridium.com/us/en/product-security
www.honeywell.com/us/en/product-security