Tridium NiagaraAX contains an unspecified flaw that may allow a remote attacker to compromise a user's system due to weak encryption and passwords stored internally on the device, in the config.bog file. With the information int his file, an attacker can "access the framework s station, which is the interface admins interact with to manage whatever the device is running". With this access, an attacker can escalate privileges locally to access the SoftJACE system (a Java-based device stack), ultimately allowing full control of the device.