CVE-2012-4701

Directory traversal vulnerability in Tridium Niagara AX 3.5, 3.6, and 3.7 allows remote attackers to read sensitive files, and consequently execute arbitrary code, by leveraging (1) valid credentials or (2) the guest feature.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tridium:niagara_ax:3.5:*:*:*:*:*:*:*
cpe:2.3:a:tridium:niagara_ax:3.6:*:*:*:*:*:*:*
cpe:2.3:a:tridium:niagara_ax:3.7:*:*:*:*:*:*:*

History

No history.

Information

Published : 2013-02-15 12:09

Updated : 2024-02-28 12:00


NVD link : CVE-2012-4701

Mitre link : CVE-2012-4701

CVE.ORG link : CVE-2012-4701


JSON object : View

Products Affected

tridium

  • niagara_ax
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')