Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Tridium

Tridium Vendor Cyber Rating & Cyber Score

tridium.com

Tridium, a global software and technology company, is the developer of the Niagara Framework®, a software platform that enables the integration of disparate systems and devices - regardless of manufacturer or communication protocol - into a unified platform that can be easily managed and controlled in real-time over the Internet. Tridium’s products and solutions are used in a variety of applications including: Building Automation Energy Management Security Management Industrial Automation Convergence Retailing Lighting Control Maintenance Repair Operations (MRO) Service Bureaus M2M (Machine-to-Machine) Total Facilities Management For additional information on how Tridium processes your personal information please visit:


Tridium A.I CyberSecurity Scoring

Tridium
Company Information
Website:http://www.tridium.com
Employees number:187
Number of followers:28,486
NAICS:5112
Industry Type:Software Development
Homepage:tridium.com
Tridium Risk Score (AI oriented)
Between 700 and 749
logo
TridiumSoftware Development
Updated:
13/08/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Tridium Global Score (TPRM)
xxxx
logo
TridiumSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Tridium
TridiumModerate
Current Score
749Ba (MODERATE)
01000
2 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
754Before Incident
Vulnerability
13 Aug 2026Tridium
Tridium, Vertiv, Trane, Liebert, Carrier and Delta Controls: 548 Internet-Exposed Building Automation Devices Run End-of-Life Products With No Future Security Patches

Critical Vulnerabilities Found in Internet-Exposed Building Automation Systems Near U.S. Data Centers

749After Incident
CRITICAL-5
LIEVERTRACARTRIDEL1786611575
Critical Vulnerabilities Found in Internet-Exposed Building Automation Systems Near U.S. Data Centers A recent security study uncovered 548 internet-exposed building automation devices near U.S. data centers running end-of-life (EOL) software, leaving them permanently unpatched against known vulnerabilities. The affected systems Tridium NiagaraAX 3.x, Trane Tracer SC, and Carrier WebCTRL 7.0 control critical infrastructure such as HVAC, cooling, power monitoring, and environmental systems, posing severe risks to data center operations. The research, part of a broader scan of industrial control systems (ICS) and building automation systems (BAS) near over 1,000 U.S. data center locations, identified 6,300 high-confidence internet-accessible devices after filtering 73,847 initial records. BACnet controllers (58%) and Fox/Niagara systems (23%) dominated the findings, with these legacy protocols often lacking modern security protections like authentication and encryption. Among the 548 EOL devices, 434 were Tridium NiagaraAX systems, vulnerable to CVE-2012-4701, a critical flaw enabling directory traversal and remote code execution (RCE). Trane Tracer SC devices were linked to CVE-2021-38450 (CVSS 9.9), an authenticated RCE vulnerability, while 64 Carrier WebCTRL 7.0 devices were exposed to CVE-2024-8525 (CVSS 10.0), allowing unauthenticated RCE via file upload. The study also flagged 237 Delta Controls enteliBUS controllers still vulnerable to CVE-2019-9569, an RCE flaw exploitable through crafted BACnet traffic, despite a patch being available for years. Geographically, California accounted for 39% of exposed devices, followed by the New York metro area. The risks are particularly acute for data centers, where a compromised BAS could disrupt cooling, trigger thermal shutdowns, or disable alarms, leading to service outages or physical damage. Vendors like Vertiv and Liebert, which specialize in precision cooling and power management, were highlighted as critical points of concern. The findings underscore the challenges of patching operational technology (OT) and BAS, where legacy systems often remain exposed due to operational constraints. Unlike traditional IT systems, these devices directly control physical processes, making their compromise a high-impact threat to data center reliability.
INCIDENT DETAILS -
TYPE
Vulnerability Exposure
IMPACT
Systems Affected: Building automation systems (BAS), HVAC, cooling, power monitoring, environmental systemsDowntime: Potential thermal shutdowns or service outagesOperational Impact: Disruption of critical data center infrastructure, potential physical damageBrand Reputation Impact: Potential reputational damage due to operational disruptions
JULY 2026
754Before Incident
JUNE 2026
754Before Incident
MAY 2026
754Before Incident
APRIL 2026
754Before Incident
MARCH 2026
753Before Incident
FEBRUARY 2026
753Before Incident
JANUARY 2026
753Before Incident
DECEMBER 2025
753Before Incident
NOVEMBER 2025
753Before Incident
OCTOBER 2025
753Before Incident
SEPTEMBER 2025
753Before Incident
SEPTEMBER 2024
753Before Incident
Vulnerability
01 Sep 2024Tridium
Tridium and Vertiv: 6,330 Internet-Exposed ICS Devices Near U.S. Data Centers Put Cooling and Power Systems at Risk

Thousands of Industrial Control Systems Exposed Near U.S. Data Centers, Raising Physical Security Risks

751After Incident
CRITICAL-2
TRIVER1786618728
Thousands of Industrial Control Systems Exposed Near U.S. Data Centers, Raising Physical Security Risks A recent internet-exposure analysis has uncovered over 6,300 high-confidence industrial control system (ICS) and building automation devices accessible near 1,063 U.S. data centers, revealing a critical but often overlooked attack surface. The research, conducted by TrendAI Research using passive Shodan data, identified publicly reachable devices including BACnet controllers, Niagara Framework instances, PLC interfaces, and power-management systems within a one-kilometer radius of documented data center locations. The findings highlight a fundamental security gap: while server networks may be hardened, the operational technology (OT) infrastructure responsible for cooling, power conditioning, and environmental monitoring often remains exposed. These systems regulate CRAC/CRAH units, chillers, UPS platforms, generators, and humidity controls, meaning a successful intrusion could allow adversaries to alter temperature setpoints, disrupt monitoring, lock out personnel, or trigger protective shutdowns leading to physical availability disruptions rather than just data loss. Key vulnerabilities identified: - BACnet devices accounted for 58% (3,664) of the exposed systems, while Niagara/Tridium systems made up 23% (1,453). - 143 multi-protocol gateways (including 125 exposing both Niagara and BACnet) were found, acting as high-value aggregation points bridging HVAC, environmental, and electrical subsystems. - Vertiv/Liebert devices, commonly used in data center cooling and power infrastructure, were also detected, suggesting some exposures may directly impact critical facility operations. Geolocation data revealed clusters of exposed devices near hyperscale data centers in Silicon Valley, though IP-based proximity does not confirm exact physical locations. The study also challenged assumptions about newer infrastructure, finding that facilities permitted since 2021 had a 13.1% exposure rate nearly triple that of pre-2010 sites potentially due to rapid deployment and complex cooling demands outpacing OT security hardening. The risks are not theoretical. Recent incidents, such as the 2024 attack on Arkansas City, Kansas’ water treatment facility, demonstrate how exposed ICS devices can lead to operational disruptions. U.S. agencies (CISA, NSA, FBI, and DOE) have warned that threat actors are actively developing tools to scan, compromise, and control ICS devices, including PLCs and OPC UA servers, often exploiting weak authentication and default credentials. While the research did not involve direct probing, the findings underscore the need for data center operators to identify and secure all internet-reachable OT systems, enforce strict network segmentation, and monitor for abnormal control traffic. The exposure of these devices even if not directly inside data centers poses a regional risk, as adversaries could exploit them to disrupt critical infrastructure.
INCIDENT DETAILS -
TYPE
Exposure of Critical Infrastructure
IMPACT
Systems Affected: Industrial control systems (ICS), building automation systems, power-management systemsDowntime: Potential physical availability disruptionsOperational Impact: Alteration of temperature setpoints, disruption of monitoring, lockout of personnel, protective shutdowns

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Tridium ?
?
What was Tridium's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Tridium's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Tridium's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Tridium's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Tridium's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Tridium's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Tridium's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Tridium's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Tridium's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Tridium's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Tridium's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Tridium's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Tridium ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Tridium's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?