A vulnerability in Nuvation Energy nCloud VPN Service allowed Network Boundary Bridging.This issue affected the nCloud VPN Service and was fixed on 2025-12-1 (December, 2025). End users do not have to take any action to mitigate the issue.
The vulnerability classified as CWE-441 (Unintended Proxy or Intermediary) occurred because the VPN service acted as an unintended intermediary enabling traffic between network segments that should have been isolated from each other. As a result, an attacker with access to one network segment could potentially reach resources in segments that should have been inaccessible. The attack vector is network-based, does not require sophisticated conditions, and successful exploitation can impact both target systems and external infrastructure.
An attacker can gain unauthorized access to resources in isolated network segments, which in industrial or critical environments may lead to violations of confidentiality, integrity, and availability of OT/IT systems.
A patch was deployed by the vendor on December 1, 2025. The vendor informs that end users do not need to take any additional actions to remediate the vulnerability — the fix was implemented on the service side.
Nuvation Energy nCloud VPN Service — versions released before 2025-12-01 (December 2025)
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X