CVE-2025-3942: Improper Output Neutralization for Logs
Improper Output Neutralization for Logs vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3942?
CVE-2025-3942 has been classified with a medium severity due to its potential for input data manipulation.
How do I fix CVE-2025-3942?
To fix CVE-2025-3942, upgrade the Tridium Niagara Framework or Niagara Enterprise Security to versions 4.14.2, 4.15.1, or 4.10.11 or higher.
What versions are affected by CVE-2025-3942?
CVE-2025-3942 affects Tridium Niagara Framework versions prior to 4.14.2, 4.15.1, and 4.10.11 as well as Niagara Enterprise Security versions prior to the same.
What type of vulnerability is CVE-2025-3942?
CVE-2025-3942 is categorized as an Improper Output Neutralization for Logs vulnerability.
Who is the vendor associated with CVE-2025-3942?
The vendor associated with CVE-2025-3942 is Tridium.