Description
CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, CLUSTERPRO X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, EXPRESSCLUSTER X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 allows an attacker sends specially crafted network packets to the product, arbitrary OS commands may be executed without authentication.
Published: 2025-11-07
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux
Nec
Nec clusterpro X
Nec clusterpro X Singleserversafe
Nec expresscluster X
Nec expresscluster X Singleserversafe
Vendors & Products Linux
Linux linux
Nec
Nec clusterpro X
Nec clusterpro X Singleserversafe
Nec expresscluster X
Nec expresscluster X Singleserversafe

Fri, 07 Nov 2025 04:15:00 +0000

Type Values Removed Values Added
Description Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5 to Ver.10.7, from Ver.10.8.21 to Ver.10.8.36, from Ver.10.9.11 to Ver.10.9.24, from Ver.10.10.21 to Ver.10.10.31, Ver.10.11.6 and UNIVERGE IX-R/IX-V Ver1.3.16, Ver1.3.21 allows an attacker sends specially crafted network packets to the product, arbitrary OS commands may be executed without authentication. CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, CLUSTERPRO X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, EXPRESSCLUSTER X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 allows an attacker sends specially crafted network packets to the product, arbitrary OS commands may be executed without authentication.

Fri, 07 Nov 2025 01:45:00 +0000

Type Values Removed Values Added
Description Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5 to Ver.10.7, from Ver.10.8.21 to Ver.10.8.36, from Ver.10.9.11 to Ver.10.9.24, from Ver.10.10.21 to Ver.10.10.31, Ver.10.11.6 and UNIVERGE IX-R/IX-V Ver1.3.16, Ver1.3.21 allows an attacker sends specially crafted network packets to the product, arbitrary OS commands may be executed without authentication.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Linux Linux
Nec Clusterpro X Clusterpro X Singleserversafe Expresscluster X Expresscluster X Singleserversafe
cve-icon MITRE

Status: PUBLISHED

Assigner: NEC

Published:

Updated: 2025-11-07T18:29:57.236Z

Reserved: 2025-10-09T06:48:19.068Z

Link: CVE-2025-11546

cve-icon Vulnrichment

Updated: 2025-11-07T18:29:20.077Z

cve-icon NVD

Status : Deferred

Published: 2025-11-07T02:15:34.180

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-11546

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-07T10:53:38Z

Weaknesses