CVE-2025-3944
HIGHTridium Niagara <4.14.2-4.15.1-4.10.11 - File Manipulation
Title source: llmDescription
Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Scores
CVSS v3
7.2
EPSS
0.0034
EPSS Percentile
56.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-732
Status
published
Products (6)
tridium/niagara
4.10u10
tridium/niagara
4.14u1
tridium/niagara
4.15
tridium/niagara_enterprise_security
4.10u10
tridium/niagara_enterprise_security
4.14u1
tridium/niagara_enterprise_security
4.15
Published
May 22, 2025
Tracked Since
Feb 18, 2026