CVE-2019-13528: Tridium NIAGARA4

Medium severity, CVSS 4.4. EPSS: 0.4% chance of exploitation in the next 30 days.

A specific utility may allow an attacker to gain read access to privileged files in the Niagara AX 3.8u4 (JACE 3e, JACE 6e, JACE 7, JACE-8000), Niagara 4.4u3 (JACE 3e, JACE 6e, JACE 7, JACE-8000), and Niagara 4.7u1 (JACE-8000, Edge 10).

Affected products

  • Tridium NIAGARA4: version 4.4u3 only; version 4.7u1 only
  • Tridium Niagara Ax: version 3.8u4 only

Published 2019-09-24. Last modified 2026-06-17.