PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-64123 Nuvation Energy CVE debrief

The CVE-2025-64123 vulnerability is an Unintended Proxy or Intermediary issue in Nuvation Energy's Multi-Stack Controller (MSC), which allows Network Boundary Bridging. This issue affects Multi-Stack Controller (MSC) through and including release 2.5.1. The CVSS score for this vulnerability is 7.9, indicating a high severity level. Defenders should assess their exposure, verify affected versions, and prioritize patching or updating to mitigate this vulnerability. The vulnerability could enable attackers to bypass security controls, making verification and patching of affected versions necessary to prevent potential attacks.

Vendor
Nuvation Energy
Product
Multi-Stack Controller (MSC)
CVSS
HIGH 7.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-02
Original CVE updated
2026-09-30
Advisory published
2026-01-02
Advisory updated
2026-09-30

Who should care

Defenders responsible for Nuvation Energy's Multi-Stack Controller (MSC) systems should assess their exposure to this vulnerability and prioritize verification and patching of affected versions.

Why it matters

The CVE-2025-64123 vulnerability in Nuvation Energy's Multi-Stack Controller (MSC) allows Network Boundary Bridging, which could enable attackers to bypass security controls. Defenders responsible for MSC systems should assess their exposure, verify affected versions, and prioritize patching or updating to mitigate this vulnerability.

  • Network Boundary Bridging could allow attackers to bypass security controls.
  • Verification of affected versions and exposure is necessary to prevent potential attacks.
  • Patching or updating affected versions of Multi-Stack Controller (MSC) is necessary to mitigate this vulnerability.

Technical summary

The CVE-2025-64123 vulnerability is an Unintended Proxy or Intermediary issue in Nuvation Energy's Multi-Stack Controller (MSC), which allows Network Boundary Bridging. This issue affects Multi-Stack Controller (MSC) through and including release 2.5.1.

Defensive priority

Defenders should prioritize verifying the affected versions of Multi-Stack Controller (MSC) and assessing their exposure to this vulnerability.

Recommended defensive actions

  • Verify the version of Multi-Stack Controller (MSC) in use and check if it is affected by this vulnerability.
  • Assess the exposure of Multi-Stack Controller (MSC) to this vulnerability.
  • Apply patches or updates to affected versions of Multi-Stack Controller (MSC) as available.

Evidence notes

The evidence for this vulnerability comes from the NVD vulnerability database and a third-party advisory from Dragos. The NVD entry is currently Analyzed.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-64123 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-64123

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-64123 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64123

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.