Tridium A.I CyberSecurity Scoring
Tridium
Company Information
Website:http://www.tridium.com
Employees number:187
Number of followers:28,486
NAICS:5112
Industry Type:Software Development
Homepage:tridium.com
Tridium Risk Score (AI oriented)
Between 700 and 749
TridiumSoftware Development
Updated:
13/08/2026
13/08/2026
749/1000
Moderate
Ba
Tridium Global Score (TPRM)
xxxx
TridiumSoftware Development
Score locked

TridiumModerate
Current Score
749Ba (MODERATE)
01000
2 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
754
Vulnerability
13 Aug 2026 • Tridium
Tridium, Vertiv, Trane, Liebert, Carrier and Delta Controls: 548 Internet-Exposed Building Automation Devices Run End-of-Life Products With No Future Security Patches
Critical Vulnerabilities Found in Internet-Exposed Building Automation Systems Near U.S. Data Centers
749
CRITICAL-5
LIEVERTRACARTRIDEL1786611575
Critical Vulnerabilities Found in Internet-Exposed Building Automation Systems Near U.S. Data Centers
A recent security study uncovered 548 internet-exposed building automation devices near U.S. data centers running end-of-life (EOL) software, leaving them permanently unpatched against known vulnerabilities. The affected systems Tridium NiagaraAX 3.x, Trane Tracer SC, and Carrier WebCTRL 7.0 control critical infrastructure such as HVAC, cooling, power monitoring, and environmental systems, posing severe risks to data center operations.
The research, part of a broader scan of industrial control systems (ICS) and building automation systems (BAS) near over 1,000 U.S. data center locations, identified 6,300 high-confidence internet-accessible devices after filtering 73,847 initial records. BACnet controllers (58%) and Fox/Niagara systems (23%) dominated the findings, with these legacy protocols often lacking modern security protections like authentication and encryption.
Among the 548 EOL devices, 434 were Tridium NiagaraAX systems, vulnerable to CVE-2012-4701, a critical flaw enabling directory traversal and remote code execution (RCE). Trane Tracer SC devices were linked to CVE-2021-38450 (CVSS 9.9), an authenticated RCE vulnerability, while 64 Carrier WebCTRL 7.0 devices were exposed to CVE-2024-8525 (CVSS 10.0), allowing unauthenticated RCE via file upload. The study also flagged 237 Delta Controls enteliBUS controllers still vulnerable to CVE-2019-9569, an RCE flaw exploitable through crafted BACnet traffic, despite a patch being available for years.
Geographically, California accounted for 39% of exposed devices, followed by the New York metro area. The risks are particularly acute for data centers, where a compromised BAS could disrupt cooling, trigger thermal shutdowns, or disable alarms, leading to service outages or physical damage. Vendors like Vertiv and Liebert, which specialize in precision cooling and power management, were highlighted as critical points of concern.
The findings underscore the challenges of patching operational technology (OT) and BAS, where legacy systems often remain exposed due to operational constraints. Unlike traditional IT systems, these devices directly control physical processes, making their compromise a high-impact threat to data center reliability.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JULY 2026
754
JUNE 2026
754
MAY 2026
754
APRIL 2026
754
MARCH 2026
753
FEBRUARY 2026
753
JANUARY 2026
753
DECEMBER 2025
753
NOVEMBER 2025
753
OCTOBER 2025
753
SEPTEMBER 2025
753
SEPTEMBER 2024
753
Vulnerability
01 Sep 2024 • Tridium
Tridium and Vertiv: 6,330 Internet-Exposed ICS Devices Near U.S. Data Centers Put Cooling and Power Systems at Risk
Thousands of Industrial Control Systems Exposed Near U.S. Data Centers, Raising Physical Security Risks
751
CRITICAL-2
TRIVER1786618728
Thousands of Industrial Control Systems Exposed Near U.S. Data Centers, Raising Physical Security Risks
A recent internet-exposure analysis has uncovered over 6,300 high-confidence industrial control system (ICS) and building automation devices accessible near 1,063 U.S. data centers, revealing a critical but often overlooked attack surface. The research, conducted by TrendAI Research using passive Shodan data, identified publicly reachable devices including BACnet controllers, Niagara Framework instances, PLC interfaces, and power-management systems within a one-kilometer radius of documented data center locations.
The findings highlight a fundamental security gap: while server networks may be hardened, the operational technology (OT) infrastructure responsible for cooling, power conditioning, and environmental monitoring often remains exposed. These systems regulate CRAC/CRAH units, chillers, UPS platforms, generators, and humidity controls, meaning a successful intrusion could allow adversaries to alter temperature setpoints, disrupt monitoring, lock out personnel, or trigger protective shutdowns leading to physical availability disruptions rather than just data loss.
Key vulnerabilities identified:
- BACnet devices accounted for 58% (3,664) of the exposed systems, while Niagara/Tridium systems made up 23% (1,453).
- 143 multi-protocol gateways (including 125 exposing both Niagara and BACnet) were found, acting as high-value aggregation points bridging HVAC, environmental, and electrical subsystems.
- Vertiv/Liebert devices, commonly used in data center cooling and power infrastructure, were also detected, suggesting some exposures may directly impact critical facility operations.
Geolocation data revealed clusters of exposed devices near hyperscale data centers in Silicon Valley, though IP-based proximity does not confirm exact physical locations. The study also challenged assumptions about newer infrastructure, finding that facilities permitted since 2021 had a 13.1% exposure rate nearly triple that of pre-2010 sites potentially due to rapid deployment and complex cooling demands outpacing OT security hardening.
The risks are not theoretical. Recent incidents, such as the 2024 attack on Arkansas City, Kansas’ water treatment facility, demonstrate how exposed ICS devices can lead to operational disruptions. U.S. agencies (CISA, NSA, FBI, and DOE) have warned that threat actors are actively developing tools to scan, compromise, and control ICS devices, including PLCs and OPC UA servers, often exploiting weak authentication and default credentials.
While the research did not involve direct probing, the findings underscore the need for data center operators to identify and secure all internet-reachable OT systems, enforce strict network segmentation, and monitor for abnormal control traffic. The exposure of these devices even if not directly inside data centers poses a regional risk, as adversaries could exploit them to disrupt critical infrastructure.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Tridium ??
What was Tridium's A.I Rankiteo Cyber Score in July 2026 ??
What was Tridium's A.I Rankiteo Cyber Score in June 2026 ??
What was Tridium's A.I Rankiteo Cyber Score in May 2026 ??
What was Tridium's A.I Rankiteo Cyber Score in April 2026 ??
What was Tridium's A.I Rankiteo Cyber Score in March 2026 ??
What was Tridium's A.I Rankiteo Cyber Score in February 2026 ??
What was Tridium's A.I Rankiteo Cyber Score in January 2026 ??
What was Tridium's A.I Rankiteo Cyber Score in December 2025 ??
What was Tridium's A.I Rankiteo Cyber Score in November 2025 ??
What was Tridium's A.I Rankiteo Cyber Score in October 2025 ??
What was Tridium's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Tridium's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Tridium ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Tridium's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?