Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.
History

Mon, 30 Mar 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Wazuh
Wazuh wazuh Provisioning Scripts
Vendors & Products Wazuh
Wazuh wazuh Provisioning Scripts

Fri, 27 Mar 2026 20:00:00 +0000

Type Values Removed Values Added
Title Various uses of curl without verifying the authenticity of the SSL certificate, leading to MITM-RCE in build infrastructure Wazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading to MITM and RCE

Fri, 27 Mar 2026 18:45:00 +0000

Type Values Removed Values Added
Description Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.
Title Various uses of curl without verifying the authenticity of the SSL certificate, leading to MITM-RCE in build infrastructure
Weaknesses CWE-295
CWE-829
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-03-27T18:16:11.058Z

Updated: 2026-03-27T19:48:43.866Z

Reserved: 2026-03-20T16:24:45.413Z

Link: CVE-2025-15612

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-27T19:16:41.690

Modified: 2026-03-30T13:26:29.793

Link: CVE-2025-15612

cve-icon Redhat

No data.