CVE-2025-3941
MEDIUMTridium Niagara <4.14.2-4.15.1-4.10.11 - Input Data Manipulation
Title source: llmDescription
Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11.Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Scores
CVSS v3
5.4
EPSS
0.0013
EPSS Percentile
32.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Classification
CWE
CWE-69
CWE-706
Status
published
Affected Products (6)
tridium/niagara
tridium/niagara
tridium/niagara
tridium/niagara_enterprise_security
tridium/niagara_enterprise_security
tridium/niagara_enterprise_security
Timeline
Published
May 22, 2025
Tracked Since
Feb 18, 2026