CVE-2025-63910
7.2Cohesity · TranZman Migration Appliance
An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows remote code execution.
Executive summary
A critical vulnerability in the Cohesity TranZman Migration Appliance allows an authenticated administrator to achieve remote code execution through the upload of a malicious patch file.
Vulnerability
This vulnerability involves an arbitrary file upload flaw within the application, allowing an attacker with Administrator privileges to upload a crafted patch file and execute arbitrary code on the underlying system.
Business impact
The ability to execute arbitrary code with administrative privileges poses a severe risk to the confidentiality, integrity, and availability of the affected system. With a CVSS score of 7.2, this high-severity flaw could allow an attacker to gain full control over the migration appliance, potentially leading to unauthorized access to sensitive data being migrated or complete system compromise.
Remediation
Immediate Action: Contact Cohesity support or consult official documentation to identify if a patched firmware or software version is available for Release 4.0 Build 14614.
Proactive Monitoring: Audit system logs for unusual file upload activities or unauthorized administrative sessions, specifically monitoring for modifications to system files or unexpected execution processes.
Compensating Controls: Restrict access to the management interface of the TranZman appliance to trusted administrative IP addresses only, and ensure that the appliance is not exposed to the public internet.
Exploitation status
Public Exploit Available: Yes — a public proof of concept is available via the researcher write-up referenced on GitHub.
Analyst recommendation
Given the potential for full system compromise, organizations should treat this vulnerability with high urgency. Administrators must restrict management access to the appliance immediately while awaiting a formal security patch from the vendor to remediate the underlying file upload vulnerability.