Critical Flaws in Niagara Framework Threaten Smart Buildings and Industrial Systems Worldwide
Jul 28, 2025
Vulnerability / Critical Infrastructure
 Cybersecurity researchers have discovered over a dozen security vulnerabilities impacting Tridium's Niagara Framework  that could allow an attacker on the same network to compromise the system under certain circumstances.  "These vulnerabilities are fully exploitable if a Niagara system is misconfigured, thereby disabling encryption on a specific network device," Nozomi Networks Labs said  in a report published last week. "If chained together, they could allow an attacker with access to the same network — such as through a Man-in-the-Middle (MiTM) position — to compromise the Niagara system."  Developed by Tridium, an independent business entity of Honeywell, the Niagara Framework is a vendor-neutral platform used to manage and control a wide range of devices from different manufacturers, such as HVAC, lighting, energy management, and security, making it a valuable solution in building management, industrial automation, and smart infrastructure environments.  I...