CVE-2025-3941: Improper Handling of Windows: DATA Alternate Data Stream
Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11.Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3941?
CVE-2025-3941 is considered a critical vulnerability due to its potential for input data manipulation.
How do I fix CVE-2025-3941?
To fix CVE-2025-3941, upgrade to Tridium Niagara Framework version 4.14.2 or higher, or to Niagara Enterprise Security version 4.15.1 or higher.
Which versions are affected by CVE-2025-3941?
CVE-2025-3941 affects Tridium Niagara Framework versions prior to 4.14.2, 4.15.1, and 4.10.11, as well as Niagara Enterprise Security versions prior to 4.14.2.
What are the consequences of exploiting CVE-2025-3941?
Exploitation of CVE-2025-3941 can lead to unauthorized input data manipulation, potentially compromising system integrity.
Who is the vendor for CVE-2025-3941?
The vendor for CVE-2025-3941 is Tridium, responsible for the Niagara Framework and Niagara Enterprise Security products.