Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-3945


Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows Command Delimiters. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.


Published

2025-05-22T13:15:57.517

Last Modified

2025-06-05T14:19:24.567

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-88
  • Type: Primary
    CWE-88

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tridium niagara 4.10u10 Yes
Application tridium niagara 4.14u1 Yes
Application tridium niagara 4.15 Yes
Application tridium niagara_enterprise_security 4.10u10 Yes
Application tridium niagara_enterprise_security 4.14u1 Yes
Application tridium niagara_enterprise_security 4.15 Yes
Operating System blackberry qnx - No

References