Improper Neutralization of Argument Delimiters in a...
High severity
Unreviewed
Published
May 22, 2025
to the GitHub Advisory Database
•
Updated May 22, 2025
Description
Published by the National Vulnerability Database
May 22, 2025
Published to the GitHub Advisory Database
May 22, 2025
Last updated
May 22, 2025
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows Command Delimiters. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.
References