CVE Explorer
CVE-2025-62785
Wazuh is a free and open source platform used for threat prevention, detection, and response. fillData() implementation does not check whether value is NULL or not before calling os_strdup() on it. A compromised agent can cause a crash of analysisd by sending a specially crafted message to the wazuh manager. An attacker who is able to craft and send an agent message to the wazuh manager can cause analysisd to crash and make it unavailable. This vulnerability is fixed in 4.10.2.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-476","description":"CWE-476: NULL Pointer Dereference","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a5258d24808267212327cf8765e16c6aecf742cf4c85167ebe69ab1dbb997d94 · sha256:abd0acde8625db5c… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-252","description":"CWE-252: Unchecked Return Value","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a5258d24808267212327cf8765e16c6aecf742cf4c85167ebe69ab1dbb997d94 · sha256:abd0acde8625db5c… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"wazuh","vendor":"wazuh","versions":[{"status":"affected","version":"< 4.10.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a5258d24808267212327cf8765e16c6aecf742cf4c85167ebe69ab1dbb997d94 · sha256:abd0acde8625db5c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.9,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a5258d24808267212327cf8765e16c6aecf742cf4c85167ebe69ab1dbb997d94 · sha256:abd0acde8625db5c… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-476","description":"CWE-476: NULL Pointer Dereference","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a5258d24808267212327cf8765e16c6aecf742cf4c85167ebe69ab1dbb997d94 · sha256:abd0acde8625db5c… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-252","description":"CWE-252: Unchecked Return Value","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a5258d24808267212327cf8765e16c6aecf742cf4c85167ebe69ab1dbb997d94 · sha256:abd0acde8625db5c… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/wazuh/wazuh/commit/17f8dc23a6211cbb398a262fcd1b0fe61b0a8eb6","tags":["x_refsource_MISC"],"url":"https://github.com/wazuh/wazuh/commit/17f8dc23a6211cbb398a262fcd1b0fe61b0a8eb6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a5258d24808267212327cf8765e16c6aecf742cf4c85167ebe69ab1dbb997d94 · sha256:abd0acde8625db5c… · /containers/cna/references/1
{"name":"https://github.com/wazuh/wazuh/security/advisories/GHSA-mqpq-pcxc-8259","tags":["x_refsource_CONFIRM"],"url":"https://github.com/wazuh/wazuh/security/advisories/GHSA-mqpq-pcxc-8259"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a5258d24808267212327cf8765e16c6aecf742cf4c85167ebe69ab1dbb997d94 · sha256:abd0acde8625db5c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.