CVE-2025-3936: Incorrect Permission Assignment for Critical Resource
Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3936?
CVE-2025-3936 is classified as a critical vulnerability due to its potential to allow unauthorized access to critical resources.
How can CVE-2025-3936 be exploited?
CVE-2025-3936 can be exploited by taking advantage of incorrectly configured access control security levels within Tridium Niagara Framework.
What versions of software are affected by CVE-2025-3936?
CVE-2025-3936 affects Tridium Niagara Framework versions prior to 4.14.2 and Tridium Niagara Enterprise Security versions prior to 4.14.2.
How do I fix CVE-2025-3936?
To fix CVE-2025-3936, it is recommended to update Tridium Niagara Framework and Niagara Enterprise Security to the latest version that is not affected.
What are the potential impacts of CVE-2025-3936?
The potential impacts of CVE-2025-3936 include unauthorized access to confidential resources and possible manipulation of critical system settings.