docs.niagara-community.comVendor advisory
https://docs.niagara-community.com/category/tech_bull CVE-2025-3940
MEDIUM
Improper Use of Validation Framework
Record summary
CVE-2025-3940 has a selected CVSS score of 5.3 (medium).
Description
Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 22, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Niagara Enterprise SecurityBrowse Tridium / Niagara Enterprise SecurityDefault status: affected | CVE List | Before 4.14.2 | affected |
| Before 4.15.1 | affected | ||
| Before 4.10.11 | affected | ||
Niagara FrameworkBrowse Tridium / Niagara FrameworkDefault status: affected | CVE List | Before 4.14.2 | affected |
| Before 4.15.1 | affected | ||
| Before 4.10.11 | affected |
References
3honeywell.comVendor advisory
https://honeywell.com/us/en/product-security nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-3940