Parameter Injection Vulnerability in Tridium Niagara Framework and Enterprise Security
CVE-2025-3943

7.5HIGH

What is CVE-2025-3943?

A parameter injection vulnerability exists in the Tridium Niagara Framework, primarily affecting the Windows, Linux, and QNX operating systems. This issue arises from the improper handling of GET request methods with sensitive query strings, which could allow for unauthorized access or manipulation of data. Tridium has advised users to upgrade their Niagara Framework and Niagara Enterprise Security to specific versions to mitigate the risks posed by this vulnerability. Users are urged to transition to versions 4.14.2u2, 4.15.u1, or 4.10u.11 to ensure enhanced security and compliance.

Affected Version(s)

Niagara Enterprise Security Windows 0

Niagara Enterprise Security Windows 0 < 4.14.2

Niagara Enterprise Security Windows 0 < 4.15.1

References

EPSS Score

7% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrea Palanca and team at Nozomi Network
.