CRITICAL🇵🇱 Wersja polska

CVE-2025-64125

CVSS 9.4v4.0pub. 2026-01-03upd. 2026-04-15

A vulnerability in Nuvation Energy nCloud VPN Service allowed Network Boundary Bridging.This issue affected the nCloud VPN Service and was fixed on 2025-12-1 (December, 2025). End users do not have to take any action to mitigate the issue.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-441 (Unintended Proxy or Intermediary) occurred because the VPN service acted as an unintended intermediary enabling traffic between network segments that should have been isolated from each other. As a result, an attacker with access to one network segment could potentially reach resources in segments that should have been inaccessible. The attack vector is network-based, does not require sophisticated conditions, and successful exploitation can impact both target systems and external infrastructure.

Impact

An attacker can gain unauthorized access to resources in isolated network segments, which in industrial or critical environments may lead to violations of confidentiality, integrity, and availability of OT/IT systems.

Mitigation & patch

A patch was deployed by the vendor on December 1, 2025. The vendor informs that end users do not need to take any additional actions to remediate the vulnerability — the fix was implemented on the service side.

Who is affected

Nuvation Energy nCloud VPN Service — versions released before 2025-12-01 (December 2025)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
VPN
CWE
References