CRITICAL🇵🇱 Wersja polska

CVE-2025-64119

CVSS 9.3v4.0pub. 2026-01-02upd. 2026-04-15

A vulnerability in Nuvation Battery Management System allows Authentication Bypass.This issue affects Battery Management System: through 2.3.9.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-603 (Use of Client-Side Authentication) means that the authentication mechanism is implemented on the client side or in a way vulnerable to bypass without possessing valid credentials. An attacker remotely, without any authentication and without user interaction, can bypass identity verification and gain unauthorized access to the system. The vulnerability affects all versions of the Battery Management System software up to and including version 2.3.9.

Impact

An attacker can gain unauthorized access to the battery management system, which may result in breach of confidentiality, integrity, and availability of the system, and in an industrial environment — potentially disrupt the operation of power infrastructure.

Mitigation & patch

Apply patches available from the manufacturer according to the references. It is recommended to isolate BMS devices from the public network and restrict network access only to trusted hosts until updates are implemented. More information in the Dragos advisory: https://www.dragos.com/community/advisories/CVE-2025-64119

Who is affected

Nuvation Battery Management System in versions up to and including 2.3.9.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References