Vulnerability Description
Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11.Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tridium | Niagara | 4.10u10 |
| Tridium | Niagara Enterprise Security | 4.10u10 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://docs.niagara-community.com/category/tech_bullPermissions Required
- https://www.honeywell.com/us/en/product-security#security-noticesVendor Advisory
FAQ
What is CVE-2025-3941?
CVE-2025-3941 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. This iss...
How severe is CVE-2025-3941?
CVE-2025-3941 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-3941?
Check the references section above for vendor advisories and patch information. Affected products include: Tridium Niagara, Tridium Niagara Enterprise Security, Microsoft Windows.