CVE Vulnerabilities

CVE-2025-3940

Improper Use of Validation Framework

Published: May 22, 2025 | Modified: Jun 04, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

Weakness

The product does not use, or incorrectly uses, an input validation framework that is provided by the source language or an independent library.

Affected Software

Name Vendor Start Version End Version
Niagara Tridium 4.10u10 (including) 4.10u10 (including)
Niagara Tridium 4.14u1 (including) 4.14u1 (including)
Niagara Tridium 4.15 (including) 4.15 (including)
Niagara_enterprise_security Tridium 4.10u10 (including) 4.10u10 (including)
Niagara_enterprise_security Tridium 4.14u1 (including) 4.14u1 (including)
Niagara_enterprise_security Tridium 4.15 (including) 4.15 (including)

Potential Mitigations

References