Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 08 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wazuh wazuh
|
|
| CPEs | cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wazuh wazuh
|
Tue, 31 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Mar 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wazuh
Wazuh wazuh Provisioning Scripts |
|
| Vendors & Products |
Wazuh
Wazuh wazuh Provisioning Scripts |
Fri, 27 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Various uses of curl without verifying the authenticity of the SSL certificate, leading to MITM-RCE in build infrastructure | Wazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading to MITM and RCE |
Fri, 27 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise. | |
| Title | Various uses of curl without verifying the authenticity of the SSL certificate, leading to MITM-RCE in build infrastructure | |
| Weaknesses | CWE-295 CWE-829 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-14T02:07:18.872Z
Reserved: 2026-03-20T16:24:45.413Z
Link: CVE-2025-15612
Updated: 2026-03-31T13:35:42.697Z
Status : Analyzed
Published: 2026-03-27T19:16:41.690
Modified: 2026-04-08T15:34:47.883
Link: CVE-2025-15612
No data.
OpenCVE Enrichment
Updated: 2026-04-08T20:01:10Z