PT-2025-22472 · Tridium · Tridium Niagara Enterprise Security +1

Published

2025-05-22

·

Updated

2025-05-27

·

CVE-2025-3945

CVSS v3.1
9.8
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

Tridium Niagara Framework versions prior to 4.14.2

Tridium Niagara Framework versions prior to 4.15.1

Tridium Niagara Framework versions prior to 4.10.11

Tridium Niagara Enterprise Security versions prior to 4.14.2

Tridium Niagara Enterprise Security versions prior to 4.15.1

Tridium Niagara Enterprise Security versions prior to 4.10.11

Description:

The issue is related to an Improper Neutralization of Argument Delimiters in a Command, also known as 'Argument Injection'. This allows Command Delimiters, which can be exploited. Tridium recommends upgrading to resolve the issue.

Recommendations:

For Tridium Niagara Framework versions prior to 4.14.2, upgrade to version 4.14.2u2.

For Tridium Niagara Framework versions prior to 4.15.1, upgrade to version 4.15.u1.

For Tridium Niagara Framework versions prior to 4.10.11, upgrade to version 4.10u.11.

For Tridium Niagara Enterprise Security versions prior to 4.14.2, upgrade to version 4.14.2u2.

For Tridium Niagara Enterprise Security versions prior to 4.15.1, upgrade to version 4.15.u1.

For Tridium Niagara Enterprise Security versions prior to 4.10.11, upgrade to version 4.10u.11.

Fix

Argument Injection

Weakness Enumeration

Related Identifiers

BDU:2025-09133
CVE-2025-3945

Affected Products

Tridium Niagara Enterprise Security
Tridium Niagara Ax Framework