Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows Command Delimiters. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
References
Link | Resource |
---|---|
https://docs.niagara-community.com/category/tech_bull | Permissions Required |
https://honeywell.com/us/en/product-security#security-notices | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
05 Jun 2025, 14:19
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:blackberry:qnx:-:*:*:*:*:*:*:* cpe:2.3:a:tridium:niagara:4.10u10:*:*:*:*:*:*:* cpe:2.3:a:tridium:niagara_enterprise_security:4.15:*:*:*:*:*:*:* cpe:2.3:a:tridium:niagara:4.15:*:*:*:*:*:*:* cpe:2.3:a:tridium:niagara_enterprise_security:4.10u10:*:*:*:*:*:*:* cpe:2.3:a:tridium:niagara:4.14u1:*:*:*:*:*:*:* cpe:2.3:a:tridium:niagara_enterprise_security:4.14u1:*:*:*:*:*:*:* |
|
First Time |
Tridium niagara
Blackberry qnx Tridium Tridium niagara Enterprise Security Blackberry |
|
References | () https://docs.niagara-community.com/category/tech_bull - Permissions Required | |
References | () https://honeywell.com/us/en/product-security#security-notices - Vendor Advisory |
23 May 2025, 15:55
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
22 May 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-22 13:15
Updated : 2025-06-05 14:19
NVD link : CVE-2025-3945
Mitre link : CVE-2025-3945
CVE.ORG link : CVE-2025-3945
JSON object : View
Products Affected
tridium
- niagara
- niagara_enterprise_security
blackberry
- qnx
CWE
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')