CVE-2025-3944: Incorrect Permission Assignment for Critical Resource
Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3944?
CVE-2025-3944 is rated as a medium-severity vulnerability due to incorrect permission assignment for critical resources.
What versions of Tridium Niagara Framework are affected by CVE-2025-3944?
CVE-2025-3944 affects Tridium Niagara Framework versions before 4.14.2, 4.15.1, and 4.10.11.
What is the impact of CVE-2025-3944?
CVE-2025-3944 can lead to unauthorized file manipulation within the affected Tridium Niagara systems.
How do I fix CVE-2025-3944?
To mitigate CVE-2025-3944, upgrade your Tridium Niagara Framework or Niagara Enterprise Security to versions 4.14.2, 4.15.1, or 4.10.11 and later.
Are there any workarounds for CVE-2025-3944?
There are no documented workarounds for CVE-2025-3944; upgrading is the recommended action.