CVE-2019-13528

A specific utility may allow an attacker to gain read access to privileged files in the Niagara AX 3.8u4 (JACE 3e, JACE 6e, JACE 7, JACE-8000), Niagara 4.4u3 (JACE 3e, JACE 6e, JACE 7, JACE-8000), and Niagara 4.7u1 (JACE-8000, Edge 10).
References
Link Resource
https://www.us-cert.gov/ics/advisories/icsa-19-262-01 Mitigation Third Party Advisory US Government Resource
https://www.us-cert.gov/ics/advisories/icsa-19-262-01 Mitigation Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tridium:niagara_ax:3.8u4:*:*:*:*:*:*:*
OR cpe:2.3:h:tridium:jace-8000:-:*:*:*:*:*:*:*
cpe:2.3:h:tridium:jace_3e:-:*:*:*:*:*:*:*
cpe:2.3:h:tridium:jace_6e:-:*:*:*:*:*:*:*
cpe:2.3:h:tridium:jace_7:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tridium:niagara4:4.4u3:*:*:*:*:*:*:*
OR cpe:2.3:h:tridium:jace-8000:-:*:*:*:*:*:*:*
cpe:2.3:h:tridium:jace_3e:-:*:*:*:*:*:*:*
cpe:2.3:h:tridium:jace_6e:-:*:*:*:*:*:*:*
cpe:2.3:h:tridium:jace_7:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:tridium:niagara4:4.7u1:*:*:*:*:*:*:*
OR cpe:2.3:h:tridium:edge_10:-:*:*:*:*:*:*:*
cpe:2.3:h:tridium:jace-8000:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:25

Type Values Removed Values Added
References () https://www.us-cert.gov/ics/advisories/icsa-19-262-01 - Mitigation, Third Party Advisory, US Government Resource () https://www.us-cert.gov/ics/advisories/icsa-19-262-01 - Mitigation, Third Party Advisory, US Government Resource

Information

Published : 2019-09-24 22:15

Updated : 2024-11-21 04:25


NVD link : CVE-2019-13528

Mitre link : CVE-2019-13528

CVE.ORG link : CVE-2019-13528


JSON object : View

Products Affected

tridium

  • jace_6e
  • niagara4
  • jace-8000
  • edge_10
  • niagara_ax
  • jace_7
  • jace_3e
CWE
CWE-285

Improper Authorization

NVD-CWE-noinfo