CVE-2025-63910

An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted patch file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cohesity:tranzman:4.0:build14614:*:*:*:*:*:*

History

05 Mar 2026, 00:25

Type Values Removed Values Added
References () https://docs.stoneram.com/index.php/Tranzman - () https://docs.stoneram.com/index.php/Tranzman - Product
References () https://gist.github.com/GregDurys/74c36c36bef81293a42022758f2736a9 - () https://gist.github.com/GregDurys/74c36c36bef81293a42022758f2736a9 - Exploit, Third Party Advisory
References () https://github.com/GregDurys/Cohesity-TranZman-CVEs - () https://github.com/GregDurys/Cohesity-TranZman-CVEs - Third Party Advisory
First Time Cohesity
Cohesity tranzman
CPE cpe:2.3:a:cohesity:tranzman:4.0:build14614:*:*:*:*:*:*

03 Mar 2026, 20:16

Type Values Removed Values Added
CWE CWE-345

03 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-03 18:16

Updated : 2026-03-05 00:25


NVD link : CVE-2025-63910

Mitre link : CVE-2025-63910

CVE.ORG link : CVE-2025-63910


JSON object : View

Products Affected

cohesity

  • tranzman
CWE
CWE-345

Insufficient Verification of Data Authenticity