Tridium Niagara AX Framework does not properly store credential data, which allows context-dependent attackers to bypass intended access restrictions by using the stored information for authentication.
https://www.tridium.com/galleries/briefings/NiagaraAX_Framework_Software_Security_Alert.pdf