PatchSiren

Nuvation Energy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Nuvation Energy CVE published 2026-01-03

CVE-2025-64125

A vulnerability in Nuvation Energy nCloud VPN Service allowed Network Boundary Bridging, with a CVSS score of 9.4 and severity of CRITICAL. The issue was fixed on December 1, 2025, and end users do not need to take action to mitigate it. This critical vulnerability affects network boundary configurations and VPN services, requiring defenders and security teams to assess exposure and verify the fix. The ac [truncated]

HIGH Nuvation Energy CVE published 2026-01-03

CVE-2025-64124

Debrief for CVE-2025-64124: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows OS Command Injection. This issue affects Multi-Stack Controller (MSC): before 2.5.1. Defenders and administrators of Nuvation Energy Multi-Stack Controller (MSC) systems should assess exposure and prioritize updates to v [truncated]

HIGH Nuvation Energy CVE published 2026-01-02

CVE-2025-64123

The CVE-2025-64123 vulnerability is an Unintended Proxy or Intermediary issue in Nuvation Energy's Multi-Stack Controller (MSC), which allows Network Boundary Bridging. This issue affects Multi-Stack Controller (MSC) through and including release 2.5.1. The CVSS score for this vulnerability is 7.9, indicating a high severity level. Defenders should assess their exposure, verify affected versions, and prio [truncated]

HIGH Nuvation Energy CVE published 2026-01-02

CVE-2025-64122

CVE-2025-64122 is a high-severity Insufficiently Protected Credentials vulnerability in Nuvation Energy Multi-Stack Controller (MSC) that allows for Signature Spoofing by Key Theft. This issue affects Multi-Stack Controller (MSC): through 2.5.1. Defenders and security teams responsible for Nuvation Energy Multi-Stack Controller (MSC) deployments should assess their exposure and prioritize verification and [truncated]

CRITICAL Nuvation Energy CVE published 2026-01-02

CVE-2025-64121

CVE-2025-64121 is an Authentication Bypass Using an Alternate Path or Channel vulnerability in Nuvation Energy Multi-Stack Controller (MSC). The issue affects Multi-Stack Controller (MSC) versions from 2.3.8 before 2.5.1. This critical vulnerability has a CVSS score of 10. The CVE record was published on 2026-01-02T22:15:44.533Z and was last modified on 2026-09-30T23:10:00.237Z. The NVD entry is currently Analyzed.

CRITICAL Nuvation Energy CVE published 2026-01-02

CVE-2025-64120

A critical vulnerability was found in Nuvation Energy's Multi-Stack Controller (MSC), which allows for OS Command Injection. This issue affects MSC versions from 2.3.8 before 2.5.1. The vulnerability is caused by improper neutralization of special elements used in an OS command. Defenders should assess exposure and prioritize patching or mitigation due to the critical severity of this vulnerability. The C [truncated]