IM
IronMonkey Threat Research

CVE-2025-3944 CRITICAL

Published: 2025-05-22 | Last Modified: 2025-06-04 | Status: Analyzed

Description

Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

Additional Descriptions (1)

Vulnerabilidad de asignación incorrecta de permisos para recursos críticos en Tridium Niagara Framework en QNX, Tridium Niagara Enterprise Security en QNX permite la manipulación de archivos. Este problema afecta a Niagara Framework: versiones anteriores a la 4.14.2, 4.15.1 y 4.10.11; Niagara Enterprise Security: versiones anteriores a la 4.14.2, 4.15.1 y 4.10.11. Tridium recomienda actualizar a Niagara Framework y Enterprise Security a las versiones 4.14.2u2, 4.15.u1 o 4.10u.11.

CVSS Metrics

Base Score: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 5.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-732
[email protected] Primary
en CWE-732

Affected Products

Vendor Product Version Update Type
tridium niagara 4.10u10 <built-in method update of dict object at 0x7c3c40d54340> Application
tridium niagara 4.14u1 <built-in method update of dict object at 0x7c3c40d574c0> Application
tridium niagara 4.15 <built-in method update of dict object at 0x7c3c476be240> Application
tridium niagara_enterprise_security 4.10u10 <built-in method update of dict object at 0x7c3bf3b4e9c0> Application
tridium niagara_enterprise_security 4.14u1 <built-in method update of dict object at 0x7c3c40d55880> Application
tridium niagara_enterprise_security 4.15 <built-in method update of dict object at 0x7c3bf3b4da40> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:tridium:niagara:4.10u10:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara:4.14u1:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara:4.15:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara_enterprise_security:4.10u10:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara_enterprise_security:4.14u1:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara_enterprise_security:4.15:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:o:blackberry:qnx:-:*:*:*:*:*:*:*
No cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
No cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Notification
Message here