CVE-2025-3938: Missing Cryptographic Step
Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3938?
CVE-2025-3938 is categorized with a high severity due to its potential for cryptanalysis.
How do I fix CVE-2025-3938?
To mitigate CVE-2025-3938, upgrade the Tridium Niagara Framework and Niagara Enterprise Security to versions 4.14.2, 4.15.1, or 4.10.11 or later.
Which products are affected by CVE-2025-3938?
CVE-2025-3938 affects versions of Tridium Niagara Framework and Niagara Enterprise Security prior to 4.14.2, 4.15.1, and 4.10.11.
What type of vulnerability is CVE-2025-3938?
CVE-2025-3938 is a Missing Cryptographic Step vulnerability.
What are the potential consequences of CVE-2025-3938?
The potential consequences of CVE-2025-3938 include the risk of unauthorized access through effective cryptanalysis.