CVE-2025-3943: Use of GET Request Method With sensitive Query Strings
Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Parameter Injection. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3943?
CVE-2025-3943 is classified as a high severity vulnerability due to its potential for parameter injection through sensitive query strings.
How do I fix CVE-2025-3943?
To fix CVE-2025-3943, update Tridium Niagara Framework and Tridium Niagara Enterprise Security to versions 4.14.2, 4.15.1, or later.
What types of systems are affected by CVE-2025-3943?
CVE-2025-3943 affects Windows, Linux, and QNX systems running specific versions of Tridium Niagara Framework and Niagara Enterprise Security.
What is a parameter injection vulnerability like CVE-2025-3943?
A parameter injection vulnerability, such as CVE-2025-3943, allows attackers to manipulate input data in request parameters, potentially compromising system security.
How can I identify if my system is vulnerable to CVE-2025-3943?
You can identify vulnerability to CVE-2025-3943 by checking the version of your Tridium Niagara Framework or Niagara Enterprise Security against the affected version list.