CVE-2025-3940: Improper Use of Validation Framework
Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3940?
CVE-2025-3940 is categorized as a high severity vulnerability due to its potential to allow input data manipulation.
How do I fix CVE-2025-3940?
To mitigate CVE-2025-3940, upgrade the Tridium Niagara Framework or Niagara Enterprise Security to version 4.14.2 or later, 4.15.1 or later, or 4.10.11 or later.
Which versions of Tridium Niagara Framework are affected by CVE-2025-3940?
CVE-2025-3940 affects Tridium Niagara Framework versions prior to 4.14.2, 4.15.1, and 4.10.11.
Which Tridium product is impacted by CVE-2025-3940?
CVE-2025-3940 impacts both Tridium Niagara Framework and Tridium Niagara Enterprise Security.
What type of vulnerability is CVE-2025-3940?
CVE-2025-3940 is classified as an improper use of validation framework vulnerability.