CVE Vulnerabilities

CVE-2025-3943

Use of GET Request Method With Sensitive Query Strings

Published: May 22, 2025 | Modified: Jun 04, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Parameter Injection. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

Weakness

The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.

Affected Software

Name Vendor Start Version End Version
Niagara Tridium 4.10u10 (including) 4.10u10 (including)
Niagara Tridium 4.14u1 (including) 4.14u1 (including)
Niagara Tridium 4.15 (including) 4.15 (including)
Niagara_enterprise_security Tridium 4.10u10 (including) 4.10u10 (including)
Niagara_enterprise_security Tridium 4.14u1 (including) 4.14u1 (including)
Niagara_enterprise_security Tridium 4.15 (including) 4.15 (including)

Potential Mitigations

References