CVE-2012-3025

The default configuration of Tridium Niagara AX Framework through 3.6 uses a cleartext base64 format for transmission of credentials in cookies, which allows remote attackers to obtain sensitive information by sniffing the network.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tridium:niagra_ax_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:tridium:niagra_ax_framework:3.5:*:*:*:*:*:*:*

Information

Published : 2012-08-16 10:38

Updated : 2012-08-16 16:13


NVD link : CVE-2012-3025

Mitre link : CVE-2012-3025


JSON object : View

Products Affected

tridium

  • niagra_ax_framework
CWE
CWE-310

Cryptographic Issues