CVE Details
Basic Information
| Title |
CVE-2025-3943 |
| Type |
cve |
| Published |
2025-05-22T13:15:57 |
| Last Seen |
2025-05-22T13:22:20 |
CVSS Information
| Base Score |
4.1 (MEDIUM) |
| Attack Vector |
NETWORK |
| Attack Complexity |
LOW |
| Privileges Required |
LOW |
| User Interaction |
REQUIRED |
| Scope |
CHANGED |
| Confidentiality Impact |
LOW |
| Integrity Impact |
NONE |
| Availability Impact |
NONE |
AI Analysis
| AI Description |
The Tridium Niagara Framework and Tridium Niagara Enterprise Security products are vulnerable to parameter injection via sensitive query strings in GET requests. This vulnerability can be exploited by an attacker with low privileges, requiring user interaction, and can lead to information disclosure. |
| AI Severity |
Medium |
| Vendor |
Tridium |
| Product |
Niagara Framework, Niagara Enterprise Security |
| Affected Version |
|
Additional Information
| CVE List |
CVE-2025-3943 |
| CWE List |
CWE-598 |
| Bulletin Family |
cve |
Description
Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Parameter Injection. This…
CVSS Score Summary
Base Score: %!f(string=#) (MEDIUM)
View Full CVE Details