CVE-2025-3944 is a critical Incorrect Permission Assignment vulnerability affecting Tridium Niagara Framework and Niagara Enterprise Security on QNX, allowing unauthorized file manipulation. This flaw impacts versions prior to 4.14.2, 4.15.1, and 4.10.11. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk as it can be exploited remotely without authentication, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high FAUCET Risk Score of 87/100 indicates significant potential impact. Organizations are strongly advised to upgrade to the recommended patched versions immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.10u10CPE matchmatch criteria | cpe:2.3:a:tridium:niagara:4.10u10:*:*:*:*:*:*:* | ||
4.14u1CPE matchmatch criteria | cpe:2.3:a:tridium:niagara:4.14u1:*:*:*:*:*:*:* | ||
4.15CPE matchmatch criteria | cpe:2.3:a:tridium:niagara:4.15:*:*:*:*:*:*:* | ||
4.10u10CPE matchmatch criteria | cpe:2.3:a:tridium:niagara_enterprise_security:4.10u10:*:*:*:*:*:*:* | ||
4.14u1CPE matchmatch criteria | cpe:2.3:a:tridium:niagara_enterprise_security:4.14u1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Technical Bulletin: Update Niagara to Address Vulnerabilities
May 22, 2025Technical Bulletin: Update Niagara to Address Vulnerabilities
May 22, 2025Technical Bulletin: Update Niagara to Address Vulnerabilities
May 22, 2025