CVE-2019-13528

A specific utility may allow an attacker to gain read access to privileged files in the Niagara AX 3.8u4 (JACE 3e, JACE 6e, JACE 7, JACE-8000), Niagara 4.4u3 (JACE 3e, JACE 6e, JACE 7, JACE-8000), and Niagara 4.7u1 (JACE-8000, Edge 10).
References
Link Resource
https://www.us-cert.gov/ics/advisories/icsa-19-262-01 Mitigation Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tridium:niagara_ax:3.8u4:*:*:*:*:*:*:*
OR cpe:2.3:h:tridium:jace-8000:-:*:*:*:*:*:*:*
cpe:2.3:h:tridium:jace_3e:-:*:*:*:*:*:*:*
cpe:2.3:h:tridium:jace_6e:-:*:*:*:*:*:*:*
cpe:2.3:h:tridium:jace_7:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tridium:niagara4:4.4u3:*:*:*:*:*:*:*
OR cpe:2.3:h:tridium:jace-8000:-:*:*:*:*:*:*:*
cpe:2.3:h:tridium:jace_3e:-:*:*:*:*:*:*:*
cpe:2.3:h:tridium:jace_6e:-:*:*:*:*:*:*:*
cpe:2.3:h:tridium:jace_7:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:tridium:niagara4:4.7u1:*:*:*:*:*:*:*
OR cpe:2.3:h:tridium:edge_10:-:*:*:*:*:*:*:*
cpe:2.3:h:tridium:jace-8000:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-09-24 22:15

Updated : 2024-02-04 20:39


NVD link : CVE-2019-13528

Mitre link : CVE-2019-13528

CVE.ORG link : CVE-2019-13528


JSON object : View

Products Affected

tridium

  • edge_10
  • jace_3e
  • niagara_ax
  • jace_6e
  • jace_7
  • niagara4
  • jace-8000
CWE
NVD-CWE-noinfo CWE-285

Improper Authorization