PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-64121 Nuvation Energy CVE debrief

CVE-2025-64121 is an Authentication Bypass Using an Alternate Path or Channel vulnerability in Nuvation Energy Multi-Stack Controller (MSC). The issue affects Multi-Stack Controller (MSC) versions from 2.3.8 before 2.5.1. This critical vulnerability has a CVSS score of 10. The CVE record was published on 2026-01-02T22:15:44.533Z and was last modified on 2026-09-30T23:10:00.237Z. The NVD entry is currently Analyzed.

Vendor
Nuvation Energy
Product
Multi-Stack Controller (MSC)
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-02
Original CVE updated
2026-09-30
Advisory published
2026-01-02
Advisory updated
2026-09-30

Who should care

Defenders responsible for Nuvation Energy Multi-Stack Controller (MSC) deployments, particularly those using versions between 2.3.8 and 2.5.1, should assess exposure and prioritize remediation.

Why it matters

CVE-2025-64121 is a critical authentication bypass vulnerability in Nuvation Energy Multi-Stack Controller (MSC) affecting versions from 2.3.8 before 2.5.1. Defenders should prioritize verifying exposure, assessing the need for an upgrade, and implementing compensating controls to mitigate potential authentication bypass.

  • Potential authentication bypass in Nuvation Energy Multi-Stack Controller (MSC) deployments
  • Possible unauthorized access to MSC systems
  • Need for verification of MSC version and exposure
  • Priority for upgrading affected MSC versions to 2.5.1 or later

Technical summary

CVE-2025-64121 is an Authentication Bypass Using an Alternate Path or Channel vulnerability in Nuvation Energy Multi-Stack Controller (MSC). The issue affects MSC versions from 2.3.8 before 2.5.1. The vulnerability has a CVSS score of 10, indicating critical severity.

Defensive priority

Defenders should prioritize verifying exposure of Nuvation Energy Multi-Stack Controller (MSC) versions between 2.3.8 and 2.5.1, assessing the need for an upgrade to version 2.5.1 or later, and implementing compensating controls to mitigate potential authentication bypass.

Recommended defensive actions

  • Verify Nuvation Energy Multi-Stack Controller (MSC) versions and assess exposure
  • Upgrade affected MSC versions to 2.5.1 or later
  • Implement compensating controls to mitigate potential authentication bypass

Evidence notes

The CVE record and NVD detail provide information on the vulnerability, its impact, and affected versions. A third-party advisory from Dragos is also referenced.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-64121 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-64121

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-64121 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64121

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.