Sunday, September 13, 2026

Tridium Niagara Framework Flaws Expose Sensitive Network Data

Cybersecurity researchers at Nozomi Networks Labs have discovered 13 critical vulnerabilities in Tridium’s widely-used Niagara Framework, potentially exposing sensitive network data across building management, industrial automation, and smart infrastructure systems worldwide.

The vulnerabilities, consolidated into 10 distinct CVEs, could allow attackers to compromise systems when encryption is misconfigured, raising significant concerns for critical infrastructure security.

Niagara Workbench main interface

Critical Infrastructure at Risk

The Tridium Niagara Framework serves as middleware connecting diverse IoT devices including HVAC systems, lighting controls, energy management, and security systems.

Developed by Tridium, a Honeywell company, the platform acts as a unified control system for operational technology environments across commercial real estate, healthcare, transportation, manufacturing, and energy sectors.

The discovered vulnerabilities are fully exploitable when Niagara systems disable encryption on network devices, creating a security warning on the dashboard that administrators may overlook.

 The attacker interacts with the Niagara station, downloads the TLS private key and finally intercepts the platform traffic.

When chained together, these flaws enable attackers with network access to execute Man-in-the-Middle attacks, potentially compromising entire building automation systems.

The research team identified vulnerabilities affecting Niagara Framework version 4.13, with vendor confirmation extending to versions 4.10u10 and earlier, plus 4.14u1 and earlier.

The most severe vulnerabilities enable lateral movement across networks and operational disruptions that could impact safety and service continuity.

CVE IDCWECVSS ScoreVector
CVE-2025-3937CWE-9167.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVE-2025-3944CWE-7327.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVE-2025-3945CWE-887.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVE-2025-3938CWE-3256.8CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
CVE-2025-3936CWE-7326.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Researchers demonstrated a sophisticated attack chain combining CVE-2025-3943 and CVE-2025-3944.

The first vulnerability exposes CSRF tokens through GET requests in system logs, while the second allows file manipulation leading to root-level remote code execution on QNX-based systems.

The attack requires network access and unencrypted Syslog configuration. Attackers can intercept anti-CSRF tokens, escalate logging levels, hijack administrator sessions, steal TLS certificates, and ultimately achieve complete system compromise.

Tridium responded swiftly with security advisories and patches addressing all identified vulnerabilities.

The company emphasizes following hardening guidelines and best practices, particularly ensuring encryption is enabled for all network communications.

Organizations using Niagara Framework should immediately apply available patches, review encryption configurations, and monitor security dashboards for warnings indicating potential misconfigurations that could expose systems to these attack vectors.

Get Free Ultimate SOC Requirements Checklist Before you build, buy, or switch your SOC for 2025 - Download Now

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News