CVE-2025-30201
Last modified
CVE-2025-30201 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows authenticated attackers to force NTLM authentication through malicious UNC paths in various agent configuration settings, potentially leading NTLM relay attacks that would result privilege escalation and remote code execution. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows authenticated attackers to force NTLM authentication through malicious UNC paths in various agent configuration settings, potentially leading NTLM relay attacks that would result privilege escalation and remote code execution. This issue has been patched in version 4.13.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wazuh | Wazuh | < 4.13.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-30201?
How severe is CVE-2025-30201?
How do I fix CVE-2025-30201?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-30196Jenkins AnchorChain Plugin 1.0 does not limit URL schemes fo…6.5
- CVE-2025-30197Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlie…3.1
- CVE-2025-30198ECOVACS robot vacuums and base stations communicate via an i…6.3
- CVE-2025-30199ECOVACS vacuum robot base stations do not validate firmware …7.5
- CVE-2025-3020An low privileged remote Attacker can execute arbitrary web …5.4
- CVE-2025-30200ECOVACS robot vacuums and base stations communicate via an i…6.3
- CVE-2025-30202vLLM is a high-throughput and memory-efficient inference and…7.5
- CVE-2025-30203Tuleap is an Open Source Suite to improve management of soft…4.8
- CVE-2025-30204golang-jwt is a Go implementation of JSON Web Tokens. Starti…7.5
- CVE-2025-30205kanidim-provision is a helper utility that uses kanidm's API…7.6
- CVE-2025-30206Dpanel is a Docker visualization panel system which provides…9.8
- CVE-2025-30207Kirby is an open-source content management system. A vulnera…7.5
Are you affected by CVE-2025-30201?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
