CVE-2025-67840

Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Build 14614 through TZM_1757588060_SEP2025_FULL.depot web application API endpoints (including Scheduler and Actions pages). The appliance directly concatenates user-controlled parameters into system commands without sufficient sanitisation, allowing an authenticated admin user to inject and execute arbitrary OS commands with root privileges. An attacker can intercept legitimate requests (e.g. during job creation or execution) using a proxy and modify parameters to include shell metacharacters, achieving remote code execution on the appliance. This completely bypasses the intended CLISH restricted shell confinement and results in full system compromise. The vulnerabilities persist in Release 4.0 Build 14614 including the latest patch (as of the time of testing) TZM_1757588060_SEP2025_FULL.depot.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cohesity:tranzman:4.0:build14614:*:*:*:*:*:*

History

17 Jun 2026, 09:58

Type Values Removed Values Added
Summary
  • (es) Múltiples vulnerabilidades de inyección de comandos del sistema operativo autenticadas existen en los puntos finales de la API de la aplicación web Cohesity (anteriormente Stone Ram) TranZman 4.0 Build 14614 hasta TZM_1757588060_SEP2025_FULL.depot (incluyendo las páginas de Programador y Acciones). El dispositivo concatena directamente parámetros controlados por el usuario en comandos del sistema sin suficiente saneamiento, permitiendo a un usuario administrador autenticado inyectar y ejecutar comandos arbitrarios del sistema operativo con privilegios de root. Un atacante puede interceptar solicitudes legítimas (por ejemplo, durante la creación o ejecución de trabajos) utilizando un proxy y modificar parámetros para incluir metacaracteres de shell, logrando la ejecución remota de código en el dispositivo. Esto elude completamente el confinamiento de shell restringido CLISH previsto y resulta en un compromiso total del sistema. Las vulnerabilidades persisten en la versión 4.0 Build 14614 incluyendo el último parche (al momento de la prueba) TZM_1757588060_SEP2025_FULL.depot.

05 Mar 2026, 00:15

Type Values Removed Values Added
References () https://cohesity.com - () https://cohesity.com - Product
References () https://gist.github.com/GregDurys/ef7fc6a36646df927374bba8e7279270 - () https://gist.github.com/GregDurys/ef7fc6a36646df927374bba8e7279270 - Exploit, Third Party Advisory
References () https://github.com/GregDurys/Cohesity-TranZman-CVEs - () https://github.com/GregDurys/Cohesity-TranZman-CVEs - Third Party Advisory
CPE cpe:2.3:a:cohesity:tranzman:4.0:build14614:*:*:*:*:*:*
First Time Cohesity
Cohesity tranzman

03 Mar 2026, 20:16

Type Values Removed Values Added
CWE CWE-78

03 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-03 18:16

Updated : 2026-06-17 09:58


NVD link : CVE-2025-67840

Mitre link : CVE-2025-67840

CVE.ORG link : CVE-2025-67840


JSON object : View

Products Affected

cohesity

  • tranzman
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')