PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-64119 Nuvation Energy CVE debrief

A vulnerability in Nuvation Battery Management System allows Authentication Bypass, with a CVSS score of 9.3, indicating critical severity. The issue affects Battery Management System through version 2.3.9. Defenders should assess exposure, particularly those managing industrial control systems and battery management solutions. The CVE record was published on 2026-01-02T22:15:44.257Z and was last modified on 2026-09-30T23:10:00.237Z.

Vendor
Nuvation Energy
Product
Battery Management System
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-02
Original CVE updated
2026-09-30
Advisory published
2026-01-02
Advisory updated
2026-09-30

Who should care

Defenders managing industrial control systems and battery management solutions should assess exposure and prioritize patching or mitigation.

Why it matters

CVE-2025-64119 is a critical Authentication Bypass vulnerability in Nuvation Battery Management System, affecting versions through 2.3.9. Defenders should assess exposure, particularly those managing industrial control systems and battery management solutions, and prioritize patching or mitigation to prevent potential unauthorized access and disruption of critical infrastructure operations.

  • Potential unauthorized access to battery management systems
  • Possible disruption of critical infrastructure operations
  • Need for verification of system versions and exposure
  • Priority for applying patches or updates

Technical summary

The vulnerability allows for Authentication Bypass in Nuvation Battery Management System, affecting versions through 2.3.9. The CVSS score of 9.3 indicates critical severity. Defenders managing industrial control systems and battery management solutions should assess exposure and prioritize patching or mitigation to prevent potential unauthorized access and disruption of critical infrastructure operations.

Defensive priority

High priority for ICS and battery management system defenders to verify exposure and apply patches.

Recommended defensive actions

  • Verify exposure of Battery Management System versions through 2.3.9
  • Apply patches or updates if available
  • Monitor system logs for potential authentication bypass attempts

Evidence notes

The CVE record and NVD detail page provide official information on the vulnerability. A source reference from Dragos offers additional context. The vulnerability affects Nuvation Battery Management System versions through 2.3.9, and defenders should verify exposure, particularly those managing industrial control systems and battery management solutions.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-64119 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-64119

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-64119 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64119

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.