CVE-2025-63911

7.2

Cohesity · TranZman Migration Appliance

Cohesity TranZman Migration Appliance Release 4.0 Build 14614 contains an authenticated command injection vulnerability that allows arbitrary code execution.

Executive summary

An authenticated command injection vulnerability in the Cohesity TranZman Migration Appliance poses a high risk of total system compromise for organizations using the affected build.

Vulnerability

This vulnerability is a command injection flaw that allows an authenticated attacker with high privileges to execute arbitrary commands on the underlying operating system. The attack requires authenticated access, as indicated by the CVSS vector PR:H.

Business impact

Successful exploitation of this vulnerability could lead to a full system compromise, allowing an attacker to gain unauthorized access to data, modify system configurations, or disrupt migration operations. With a CVSS score of 7.2, this issue represents a significant risk to the integrity and availability of the migration environment, potentially impacting data migration timelines and sensitive project information.

Remediation

Immediate Action: Organizations should restrict access to the appliance to trusted personnel only and contact Cohesity support to determine if a patch or configuration workaround is available for this specific build.

Proactive Monitoring: Security teams should monitor system logs for unusual process execution, unexpected shell spawning, or unauthorized command-line activity originating from the appliance.

Compensating Controls: Implement strict network segmentation to limit the attack surface of the appliance and employ WAF rules to inspect traffic for common command injection patterns if the appliance is accessible over a network.

Exploitation status

Public Exploit Available: Yes, a published PoC exists, attributed to the technical write-up referenced in the CVE record.

Analyst recommendation

Given the capability for command injection and the existence of a public proof-of-concept, this vulnerability should be treated as a high-priority item. Administrators must audit current access controls immediately and coordinate with the vendor to verify the availability of a firmware update or security patch to eliminate the underlying flaw.

More Cohesity CVEs

Sources