CVE-2025-3939

Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11.Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:tridium:niagara:4.10u10:*:*:*:*:*:*:*
cpe:2.3:a:tridium:niagara:4.14u1:*:*:*:*:*:*:*
cpe:2.3:a:tridium:niagara:4.15:*:*:*:*:*:*:*
cpe:2.3:a:tridium:niagara_enterprise_security:4.10u10:*:*:*:*:*:*:*
cpe:2.3:a:tridium:niagara_enterprise_security:4.14u1:*:*:*:*:*:*:*
cpe:2.3:a:tridium:niagara_enterprise_security:4.15:*:*:*:*:*:*:*
OR cpe:2.3:o:blackberry:qnx:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

04 Jun 2025, 19:29

Type Values Removed Values Added
CWE CWE-203
References () https://docs.niagara-community.com/category/tech_bull - () https://docs.niagara-community.com/category/tech_bull - Permissions Required
References () https://honeywell.com/us/en/product-security#security-notices - () https://honeywell.com/us/en/product-security#security-notices - Vendor Advisory
CPE cpe:2.3:a:tridium:niagara_enterprise_security:4.15:*:*:*:*:*:*:*
cpe:2.3:a:tridium:niagara:4.10u10:*:*:*:*:*:*:*
cpe:2.3:a:tridium:niagara:4.14u1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:tridium:niagara:4.15:*:*:*:*:*:*:*
cpe:2.3:o:blackberry:qnx:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:tridium:niagara_enterprise_security:4.14u1:*:*:*:*:*:*:*
cpe:2.3:a:tridium:niagara_enterprise_security:4.10u10:*:*:*:*:*:*:*
First Time Linux
Tridium niagara Enterprise Security
Blackberry
Tridium niagara
Linux linux Kernel
Microsoft windows
Microsoft
Tridium
Blackberry qnx

23 May 2025, 15:55

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de discrepancia de respuesta observable en Tridium Niagara Framework para Windows, Linux y QNX, Tridium Niagara Enterprise Security para Windows, Linux y QNX permite el criptoanálisis. Este problema afecta a Niagara Framework: versiones anteriores a la 4.14.2, 4.15.1 y 4.10.11; Niagara Enterprise Security: versiones anteriores a la 4.14.2, 4.15.1 y 4.10.11. Tridium recomienda actualizar a las versiones 4.14.2u2, 4.15.u1 o 4.10u.11 de Niagara Framework y Enterprise Security.

22 May 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-22 13:15

Updated : 2025-06-04 19:29


NVD link : CVE-2025-3939

Mitre link : CVE-2025-3939

CVE.ORG link : CVE-2025-3939


JSON object : View

Products Affected

tridium

  • niagara_enterprise_security
  • niagara

linux

  • linux_kernel

microsoft

  • windows

blackberry

  • qnx
CWE
CWE-204

Observable Response Discrepancy

CWE-203

Observable Discrepancy