CVE-2025-3940
Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS probability
- 0.36%
- CWE
- CWE-1173
- Published
- 2025-05-22
- Last modified
- 2026-03-12
Affected products
- Tridium Niagara Framework
- Tridium Niagara Enterprise Security
Weakness type
Related vulnerabilities
- CVE-2024-58360 — stoatchat before 0.7.8 Unrestricted Account Creation
- CVE-2026-33674 — PrestaShop: Improper Use of Validation Framework
- CVE-2025-48490 — Laravel Rest Api has a Search Validation Bypass
- CVE-2023-30949 — CVE-2023-30949
- CVE-2022-1414 — 3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An...
- CVE-2020-1640 — Junos OS: Receipt of certain genuine BGP packets from any BGP Speaker causes RPD to crash.