CVE-2025-63909

HIGH

Cohesity TranZman 4.0 Build 14614 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers to escalate privileges to root and read and write arbitrary files.

Scores

CVSS v3 7.2
EPSS 0.0001
EPSS Percentile 1.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
cohesity/tranzman 4.0 build14614
Published Mar 03, 2026
Tracked Since Mar 04, 2026