CVE-2025-63912

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows attackers to easily decrypt sensitive data, including credentials, due to the use of a weak encryption method in the Cohesity TranZman Migration Appliance. To exploit this flaw, an attacker would need access to the encrypted data, making it critical to secure the environment where this appliance is used.

Technical Description

Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to use a weak cryptography algorithm for data encryption, allowing attackers to trivially reverse the encyption and expose credentials.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactNone
Availability ImpactNone
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References