Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-3941


Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11.Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.


Published

2025-05-22T13:15:57.000

Last Modified

2025-06-04T19:28:23.770

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-69
  • Type: Primary
    CWE-706

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tridium niagara 4.10u10 Yes
Application tridium niagara 4.14u1 Yes
Application tridium niagara 4.15 Yes
Application tridium niagara_enterprise_security 4.10u10 Yes
Application tridium niagara_enterprise_security 4.14u1 Yes
Application tridium niagara_enterprise_security 4.15 Yes
Operating System microsoft windows - No

References