IM
IronMonkey Threat Research

CVE-2025-3942 HIGH

Published: 2025-05-22 | Last Modified: 2025-06-04 | Status: Analyzed

Description

Improper Output Neutralization for Logs vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

Additional Descriptions (1)

La vulnerabilidad de neutralización de salida incorrecta para registros en Tridium Niagara Framework (Windows, Linux, QNX) y Tridium Niagara Enterprise Security (Windows, Linux, QNX) permite la manipulación de datos de entrada. Este problema afecta a Niagara Framework: versiones anteriores a la 4.14.2, 4.15.1 y 4.10.11; y a Niagara Enterprise Security: versiones anteriores a la 4.14.2, 4.15.1 y 4.10.11. Tridium recomienda actualizar a las versiones 4.14.2u2, 4.15.u1 o 4.10u.11 de Niagara Framework y Enterprise Security.

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactHIGH
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-117
[email protected] Primary
en CWE-116

Affected Products

Vendor Product Version Update Type
tridium niagara 4.10u10 <built-in method update of dict object at 0x7c3bf3a1e340> Application
tridium niagara 4.14u1 <built-in method update of dict object at 0x7c3c40d58740> Application
tridium niagara 4.15 <built-in method update of dict object at 0x7c3c2ab13100> Application
tridium niagara_enterprise_security 4.10u10 <built-in method update of dict object at 0x7c3c29759640> Application
tridium niagara_enterprise_security 4.14u1 <built-in method update of dict object at 0x7c3bf3a1e9c0> Application
tridium niagara_enterprise_security 4.15 <built-in method update of dict object at 0x7c3bf3a1f400> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:tridium:niagara:4.10u10:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara:4.14u1:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara:4.15:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara_enterprise_security:4.10u10:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara_enterprise_security:4.14u1:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara_enterprise_security:4.15:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:o:blackberry:qnx:-:*:*:*:*:*:*:*
No cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
No cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Notification
Message here