CVE-2025-3939: Observable Response Discrepancy
Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11.Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3939?
CVE-2025-3939 is classified as a critical vulnerability due to its potential for cryptanalysis in the affected systems.
How do I fix CVE-2025-3939?
To remediate CVE-2025-3939, upgrade to the latest versions of the Tridium Niagara Framework and Niagara Enterprise Security, specifically versions 4.14.2 and above, 4.15.1 and above, or 4.10.11 and above.
What systems are affected by CVE-2025-3939?
CVE-2025-3939 affects the Tridium Niagara Framework and Tridium Niagara Enterprise Security prior to versions 4.14.2, 4.15.1, and 4.10.11.
What type of vulnerability is CVE-2025-3939?
CVE-2025-3939 is categorized as an Observable Response Discrepancy vulnerability, which can lead to potential cryptanalysis.
Is CVE-2025-3939 exploitable remotely?
CVE-2025-3939 can potentially be exploited remotely, allowing attackers to perform cryptanalysis on the affected systems.