CVE Vulnerabilities

CVE-2025-3941

Improper Handling of Windows ::DATA Alternate Data Stream

Published: May 22, 2025 | Modified: Jun 04, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11.Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

Weakness

The product does not properly prevent access to, or detect usage of, alternate data streams (ADS).

Affected Software

NameVendorStart VersionEnd Version
NiagaraTridium4.10u10 (including)4.10u10 (including)
NiagaraTridium4.14u1 (including)4.14u1 (including)
NiagaraTridium4.15 (including)4.15 (including)
Niagara_enterprise_securityTridium4.10u10 (including)4.10u10 (including)
Niagara_enterprise_securityTridium4.14u1 (including)4.14u1 (including)
Niagara_enterprise_securityTridium4.15 (including)4.15 (including)

Potential Mitigations

References