Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Jun 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Blackberry
Blackberry qnx Linux Linux linux Kernel Microsoft Microsoft windows Tridium Tridium niagara Tridium niagara Enterprise Security |
|
CPEs | cpe:2.3:a:tridium:niagara:4.10u10:*:*:*:*:*:*:* cpe:2.3:a:tridium:niagara:4.14u1:*:*:*:*:*:*:* cpe:2.3:a:tridium:niagara:4.15:*:*:*:*:*:*:* cpe:2.3:a:tridium:niagara_enterprise_security:4.10u10:*:*:*:*:*:*:* cpe:2.3:a:tridium:niagara_enterprise_security:4.14u1:*:*:*:*:*:*:* cpe:2.3:a:tridium:niagara_enterprise_security:4.15:*:*:*:*:*:*:* cpe:2.3:o:blackberry:qnx:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Blackberry
Blackberry qnx Linux Linux linux Kernel Microsoft Microsoft windows Tridium Tridium niagara Tridium niagara Enterprise Security |
Thu, 22 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 22 May 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11. | |
Title | Incorrect Permission Assignment for Critical Resource | |
Weaknesses | CWE-732 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Honeywell
Published: 2025-05-22T12:44:55.511Z
Updated: 2025-05-22T13:17:37.301Z
Reserved: 2025-04-25T15:21:20.179Z
Link: CVE-2025-3944

Updated: 2025-05-22T13:17:34.361Z

Status : Analyzed
Published: 2025-05-22T13:15:57.387
Modified: 2025-06-04T19:27:07.777
Link: CVE-2025-3944

No data.