A timeout during a TLS handshake can result in the connection failing to terminate. This can result in a Niagara thread hanging and requires a manual restart of Niagara (Versions 4.6.96.28, 4.7.109.20, 4.7.110.32, 4.8.0.110) and Niagara Enterprise Security (Versions 2.4.31, 2.4.45, 4.8.0.35) to correct.
Un tiempo de espera durante un protocolo de enlace TLS puede resultar en que la conexión falle al terminar. Esto puede resultar en un bloqueo del hilo o subproceso de Niagara y requiere un reinicio manual de Niagara (versiones 4.6.96.28, 4.7.109.20, 4.7.110.32, 4.8.0.110) y Niagara Enterprise Security (versiones 2.4.31, 2.4.45, 4.8.0.35 ) parra corregir
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
| Attack Vector | ADJACENT_NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | LOW |
AV:A/AC:L/Au:N/C:N/I:N/A:P
| Access Vector | ADJACENT_NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | PARTIAL |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-1088
|
| [email protected] | Primary |
en
NVD-CWE-Other
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| tridium | niagara | 4.6.96.28 | <built-in method update of dict object at 0x7c3c2ab0fd80> | Application |
| tridium | niagara | 4.7.109.20 | <built-in method update of dict object at 0x7c3c2ab0ce80> | Application |
| tridium | niagara | 4.7.110.32 | <built-in method update of dict object at 0x7c3c40d4f800> | Application |
| tridium | niagara | 4.8.0.110 | <built-in method update of dict object at 0x7c3c2ab0cd40> | Application |
| tridium | niagara_enterprise_security | 2.4.31 | <built-in method update of dict object at 0x7c3c2ab0de80> | Application |
| tridium | niagara_enterprise_security | 2.4.45 | <built-in method update of dict object at 0x7c3c2ab0fa80> | Application |
| tridium | niagara_enterprise_security | 4.8.0.35 | <built-in method update of dict object at 0x7c3c40d4f340> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:tridium:niagara:4.6.96.28:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:tridium:niagara:4.7.109.20:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:tridium:niagara:4.7.110.32:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:tridium:niagara:4.8.0.110:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:tridium:niagara_enterprise_security:2.4.31:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:tridium:niagara_enterprise_security:2.4.45:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:tridium:niagara_enterprise_security:4.8.0.35:*:*:*:*:*:*:* |