PT-2026-1134 · Nuvation · Nuvation Battery Management System

CVE-2025-64119

·

Publicado

2025-01-13

·

Atualizado

2026-01-03

CVSS v4.0

9.3

Crítica

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:P/AU:Y
Name of the Vulnerable Software and Affected Versions Nuvation Battery Management System versions through 2.3.9
Description A flaw exists in the Nuvation Battery Management System that permits authentication bypass. This allows unauthorized access to critical battery management functions via the network.
Recommendations Versions prior to 2.3.9 should be updated.

Correção

Insufficiently Protected Credentials

OS Command Injection

Authentication Bypass Using an Alternate Path or Channel

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-00777
BDU:2026-00778
BDU:2026-00779
BDU:2026-00780
BDU:2026-00781
CVE-2025-64119

Produtos afetados

Nuvation Battery Management System