CVE-2025-3937: Use of Password Hash with Insufficient Computational Effort
Use of Password Hash With Insufficient Computational Effort vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3937?
CVE-2025-3937 is classified as a medium severity vulnerability allowing for effective cryptanalysis of password hashes.
How do I fix CVE-2025-3937?
To mitigate CVE-2025-3937, upgrade your Tridium Niagara Framework and Niagara Enterprise Security software to version 4.14.2 or later.
What systems are affected by CVE-2025-3937?
CVE-2025-3937 affects the Tridium Niagara Framework and Niagara Enterprise Security on Windows, Linux, and QNX platforms.
What type of vulnerability is CVE-2025-3937?
CVE-2025-3937 is a vulnerability related to the use of password hashing with insufficient computational effort.
Can CVE-2025-3937 lead to data breaches?
Yes, CVE-2025-3937 can potentially lead to unauthorized access due to weak password hash security.