CVE-2025-63909
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
03/03/2026
Last modified:
03/03/2026
Description
Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers to escalate privileges to root and read and write arbitrary files.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH



