CVE-2025-62785
HIGHDescription
Wazuh is a free and open source platform used for threat prevention, detection, and response. fillData() implementation does not check whether value is NULL or not before calling os_strdup() on it. A compromised agent can cause a crash of analysisd by sending a specially crafted message to the wazuh manager. An attacker who is able to craft and send an agent message to the wazuh manager can cause analysisd to crash and make it unavailable. This vulnerability is fixed in 4.10.2.
Is your site exposed to CVE-2025-62785?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| wazuh | wazuh |
References
Frequently Asked Questions
What is CVE-2025-62785? +
How severe is CVE-2025-62785? +
What products are affected by CVE-2025-62785? +
How do I check if I'm vulnerable to CVE-2025-62785? +
Related Vulnerabilities
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbitrary …
Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that …
The Ember ZNet stack’s packet buffer manager may read out of bound memory leading to an assert, causing a Denial …
wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table …
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an …
Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic …