PatchSiren cyber security CVE debrief
CVE-2025-64123 Nuvation Energy CVE debrief
The CVE-2025-64123 vulnerability is an Unintended Proxy or Intermediary issue in Nuvation Energy's Multi-Stack Controller (MSC), which allows Network Boundary Bridging. This issue affects Multi-Stack Controller (MSC) through and including release 2.5.1. The CVSS score for this vulnerability is 7.9, indicating a high severity level. Defenders should assess their exposure, verify affected versions, and prioritize patching or updating to mitigate this vulnerability. The vulnerability could enable attackers to bypass security controls, making verification and patching of affected versions necessary to prevent potential attacks.
- Vendor
- Nuvation Energy
- Product
- Multi-Stack Controller (MSC)
- CVSS
- HIGH 7.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-02
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-02
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for Nuvation Energy's Multi-Stack Controller (MSC) systems should assess their exposure to this vulnerability and prioritize verification and patching of affected versions.
Why it matters
The CVE-2025-64123 vulnerability in Nuvation Energy's Multi-Stack Controller (MSC) allows Network Boundary Bridging, which could enable attackers to bypass security controls. Defenders responsible for MSC systems should assess their exposure, verify affected versions, and prioritize patching or updating to mitigate this vulnerability.
- Network Boundary Bridging could allow attackers to bypass security controls.
- Verification of affected versions and exposure is necessary to prevent potential attacks.
- Patching or updating affected versions of Multi-Stack Controller (MSC) is necessary to mitigate this vulnerability.
Technical summary
The CVE-2025-64123 vulnerability is an Unintended Proxy or Intermediary issue in Nuvation Energy's Multi-Stack Controller (MSC), which allows Network Boundary Bridging. This issue affects Multi-Stack Controller (MSC) through and including release 2.5.1.
Defensive priority
Defenders should prioritize verifying the affected versions of Multi-Stack Controller (MSC) and assessing their exposure to this vulnerability.
Recommended defensive actions
- Verify the version of Multi-Stack Controller (MSC) in use and check if it is affected by this vulnerability.
- Assess the exposure of Multi-Stack Controller (MSC) to this vulnerability.
- Apply patches or updates to affected versions of Multi-Stack Controller (MSC) as available.
Evidence notes
The evidence for this vulnerability comes from the NVD vulnerability database and a third-party advisory from Dragos. The NVD entry is currently Analyzed.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-64123 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-64123
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-64123 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64123
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.dragos.com/community/advisories/CVE-2025-64119
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.