CVE-2025-63910
Last modified
CVE-2025-63910 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted patch file.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted patch file.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Cohesity | Tranzman | 4.0 | Build14614 |
References
- https://gist.github.com/GregDurys/74c36c36bef81293a42022758f2736a9Exploit, Third Party Advisory
- https://github.com/GregDurys/Cohesity-TranZman-CVEsThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-63910?
How severe is CVE-2025-63910?
How do I fix CVE-2025-63910?
Are you affected by CVE-2025-63910?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
