CVE-2025-3943 is a high-severity vulnerability (CVSS 7.5) in Tridium Niagara Framework and Enterprise Security that allows parameter injection due to the use of GET requests with sensitive query strings. This affects various versions of Niagara Framework and Enterprise Security on Windows, Linux, and QNX, specifically those before 4.14.2, 4.15.1, and 4.10.11. The vulnerability has a low attack complexity and no user interaction is required, posing a significant risk of high confidentiality impact. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.10u10CPE matchmatch criteria | cpe:2.3:a:tridium:niagara:4.10u10:*:*:*:*:*:*:* | ||
4.14u1CPE matchmatch criteria | cpe:2.3:a:tridium:niagara:4.14u1:*:*:*:*:*:*:* | ||
4.15CPE matchmatch criteria | cpe:2.3:a:tridium:niagara:4.15:*:*:*:*:*:*:* | ||
4.10u10CPE matchmatch criteria | cpe:2.3:a:tridium:niagara_enterprise_security:4.10u10:*:*:*:*:*:*:* | ||
4.14u1CPE matchmatch criteria | cpe:2.3:a:tridium:niagara_enterprise_security:4.14u1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Technical Bulletin: Update Niagara to Address Vulnerabilities
May 22, 2025Technical Bulletin: Update Niagara to Address Vulnerabilities
May 22, 2025Technical Bulletin: Update Niagara to Address Vulnerabilities
May 22, 2025