CVE-2025-3937
HIGHTridium Niagara <4.14.2-4.15.1-4.10.11 - Cryptanalysis
Title source: llmDescription
Use of Password Hash With Insufficient Computational Effort vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Scores
CVSS v3
7.7
EPSS
0.0005
EPSS Percentile
15.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Classification
CWE
CWE-916
Status
published
Affected Products (6)
tridium/niagara
tridium/niagara
tridium/niagara
tridium/niagara_enterprise_security
tridium/niagara_enterprise_security
tridium/niagara_enterprise_security
Timeline
Published
May 22, 2025
Tracked Since
Feb 18, 2026