Inclusion of Functionality from Untrusted Control Sphere
CVE-2025-67900
Summary
NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.
- HIGH
- LOCAL
- HIGH
- CHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-829 - Inclusion of Functionality from Untrusted Control Sphere
The software imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
References
Advisory Timeline
- Published