CVE-2025-3941

MEDIUM

Tridium Niagara <4.14.2-4.15.1-4.10.11 - Input Data Manipulation

Title source: llm

Description

Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11.Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

Scores

CVSS v3 5.4
EPSS 0.0013
EPSS Percentile 32.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Classification

CWE
CWE-69 CWE-706
Status published

Affected Products (6)

tridium/niagara
tridium/niagara
tridium/niagara
tridium/niagara_enterprise_security
tridium/niagara_enterprise_security
tridium/niagara_enterprise_security

Timeline

Published May 22, 2025
Tracked Since Feb 18, 2026