Database/Control plane, storage & DevOps
Tridium Niagara AX (<=3.8) and Niagara 4 (<=4.4) framework: Log into the Niagara platform with a disabled account name
Impact
Log into the Niagara platform with a disabled account name and a blank password and you get administrator. Niagara is the integration layer a very large share of datacenters use to tie CRAC/CRAH, chillers, generators, metering and sometimes access control into one supervisory system, so administrator on the Niagara station is administrator over the whole facility control surface at once. That means arbitrary writes to cooling setpoints and fan commands across every integrated subsystem, the ability to disable alarms and schedules, and access to the credential store Niagara keeps for its downstream drivers - which is how a BMS compromise turns into compromise of the chiller, the ATS controller and the metering network in one step. For a GPU operator the headline is simple: one blank password and the hall's thermal envelope is under attacker control, with minutes of margin before accelerators shut down.
Who can reach it
Unauthenticated login against the Niagara station's web or Fox interface on the facility network. Niagara stations are one of the most consistently internet-exposed classes of building controller in existence - integrators publish them for remote support and forget - so treat internet exposure as likely rather than exceptional until you have checked your own external attack surface for the Niagara Fox port and the station web UI.
What to do
Patchable via a Niagara framework upgrade (AX 3.8U1 / Niagara 4.4U1 or later), performed by the systems integrator who owns the station. This is a software upgrade on the supervisor plus a JACE controller update, so it needs a maintenance window and a contractor but not a cooling outage. Do it, then audit the account list for disabled-but-present accounts, and pull the station off any internet-facing interface. Because Niagara stations are so often integrator-managed rather than operator-managed, the harder task is organisational: find out who actually holds the platform credentials for your station, whether the integrator has a permanent remote path in, and whether that path is MFA'd. In a leased colo the station belongs to the landlord and typically serves the entire building - demand the framework version and the remote-access architecture in writing.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.