9.8

CVE-2025-3941

Improper Handling of Windows: DATA Alternate Data Stream

Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11.Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TridiumNiagara Version4.10u10
   MicrosoftWindows Version-
TridiumNiagara Version4.14u1
   MicrosoftWindows Version-
TridiumNiagara Version4.15
   MicrosoftWindows Version-
TridiumNiagara Enterprise Security Version4.10u10
   MicrosoftWindows Version-
TridiumNiagara Enterprise Security Version4.14u1
   MicrosoftWindows Version-
TridiumNiagara Enterprise Security Version4.15
   MicrosoftWindows Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.369
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
psirt@honeywell.com 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-69 Improper Handling of Windows ::DATA Alternate Data Stream

The product does not properly prevent access to, or detect usage of, alternate data streams (ADS).

CWE-706 Use of Incorrectly-Resolved Name or Reference

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

https://www.honeywell.com/us/en/product-security#security-notices
Vendor Advisory
https://docs.niagara-community.com/category/tech_bull
Permissions Required