{"id":"CVE-2025-15612","title":"Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation","summary":"Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-midd…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-295","CWE-829"],"vendor":"wazuh","product":"wazuh","affected":["wazuh >= 4.1.3, < 4.14.0"],"patched":["wazuh 4.14.0"],"published":"2026-03-27","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-15612","references":[{"url":"https://github.com/wazuh/wazuh/security/advisories/GHSA-wvg9-7q49-c7mg","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/various-uses-of-curl-without-verifying-the-authenticity-of-the-ssl-certificate-leading-to-mitm-rce-in-build-infrastructure","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.00216,"epssPercentile":0.10852,"ingestedAt":"2026-09-30T22:27:27.743Z","slug":"CVE-2025-15612","body":"## Overview\n\nWazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.\n\n## Affected\n\n- `wazuh >= 4.1.3, < 4.14.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `wazuh 4.14.0`","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}