CVE-2025-15612
⚪ Do wiadomości
Użycie flagi -k w skryptach Wazuh umożliwia ataki typu man-in-the-middle i zdalne wykonanie kodu.
CVSS
4.8
EPSS
0.2%
Exploit
poc
Vendor
wazuh
Opis źródłowy (NVD)
Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.
exploit rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 4.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-03-27 19:16:41 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 09:10:00 UTC |
Referencje
- https://github.com/wazuh/wazuh/security/advisories/GHSA-wvg9-7q49-c7mg ([email protected]) [Exploit, Vendor Advisory]
- https://www.vulncheck.com/advisories/various-uses-of-curl-without-verifying-the-authenticity-of-the-ssl-certificate-leading-to-mitm-rce-in-build-infrastructure ([email protected]) [Third Party Advisory]