PatchSiren cyber security CVE debrief
CVE-2025-64119 Nuvation Energy CVE debrief
A vulnerability in Nuvation Battery Management System allows Authentication Bypass, with a CVSS score of 9.3, indicating critical severity. The issue affects Battery Management System through version 2.3.9. Defenders should assess exposure, particularly those managing industrial control systems and battery management solutions. The CVE record was published on 2026-01-02T22:15:44.257Z and was last modified on 2026-09-30T23:10:00.237Z.
- Vendor
- Nuvation Energy
- Product
- Battery Management System
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-02
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-02
- Advisory updated
- 2026-09-30
Who should care
Defenders managing industrial control systems and battery management solutions should assess exposure and prioritize patching or mitigation.
Why it matters
CVE-2025-64119 is a critical Authentication Bypass vulnerability in Nuvation Battery Management System, affecting versions through 2.3.9. Defenders should assess exposure, particularly those managing industrial control systems and battery management solutions, and prioritize patching or mitigation to prevent potential unauthorized access and disruption of critical infrastructure operations.
- Potential unauthorized access to battery management systems
- Possible disruption of critical infrastructure operations
- Need for verification of system versions and exposure
- Priority for applying patches or updates
Technical summary
The vulnerability allows for Authentication Bypass in Nuvation Battery Management System, affecting versions through 2.3.9. The CVSS score of 9.3 indicates critical severity. Defenders managing industrial control systems and battery management solutions should assess exposure and prioritize patching or mitigation to prevent potential unauthorized access and disruption of critical infrastructure operations.
Defensive priority
High priority for ICS and battery management system defenders to verify exposure and apply patches.
Recommended defensive actions
- Verify exposure of Battery Management System versions through 2.3.9
- Apply patches or updates if available
- Monitor system logs for potential authentication bypass attempts
Evidence notes
The CVE record and NVD detail page provide official information on the vulnerability. A source reference from Dragos offers additional context. The vulnerability affects Nuvation Battery Management System versions through 2.3.9, and defenders should verify exposure, particularly those managing industrial control systems and battery management solutions.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-64119 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-64119
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-64119 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64119
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.dragos.com/community/advisories/CVE-2025-64119
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.