CVE-2025-64122

I

nsufficiently Protected Credentials vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Signature Spoofing by Key Theft.This issue affects Multi-Stack Controller (MSC): through 2.5.1.

References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nuvationenergy:nplatform:*:*:*:*:*:*:*:*
OR cpe:2.3:h:nuvationenergy:nuvmsc3-04s-c:-:*:*:*:*:*:*:*
cpe:2.3:h:nuvationenergy:nuvmsc3-08s-c:-:*:*:*:*:*:*:*
cpe:2.3:h:nuvationenergy:nuvmsc3-12s-c:-:*:*:*:*:*:*:*
cpe:2.3:h:nuvationenergy:nuvmsc3-16s-c:-:*:*:*:*:*:*:*

History

26 Feb 2026, 19:59

Type Values Removed Values Added
References () https://www.dragos.com/community/advisories/CVE-2025-64119 - () https://www.dragos.com/community/advisories/CVE-2025-64119 - Third Party Advisory
CPE cpe:2.3:h:nuvationenergy:nuvmsc3-04s-c:-:*:*:*:*:*:*:*
cpe:2.3:h:nuvationenergy:nuvmsc3-08s-c:-:*:*:*:*:*:*:*
cpe:2.3:a:nuvationenergy:nplatform:*:*:*:*:*:*:*:*
cpe:2.3:h:nuvationenergy:nuvmsc3-16s-c:-:*:*:*:*:*:*:*
cpe:2.3:h:nuvationenergy:nuvmsc3-12s-c:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Nuvationenergy
Nuvationenergy nuvmsc3-08s-c
Nuvationenergy nuvmsc3-04s-c
Nuvationenergy nplatform
Nuvationenergy nuvmsc3-12s-c
Nuvationenergy nuvmsc3-16s-c

02 Jan 2026, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-02 22:15

Updated : 2026-02-26 19:59


NVD link : CVE-2025-64122

Mitre link : CVE-2025-64122

CVE.ORG link : CVE-2025-64122


JSON object : View

CWE
CWE-522

Insufficiently Protected Credentials