Remote Code Execution Vulnerability in NSF Unidata NetCDF-C
CVE-2025-14933

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
23 December 2025

What is CVE-2025-14933?

A vulnerability exists in NSF Unidata NetCDF-C due to inadequate validation of user-supplied data when parsing NC variable integers. This flaw may be exploited by an attacker to induce an integer overflow, allowing the execution of arbitrary code in the context of the current user. Successful exploitation typically requires user interaction, such as visiting a malicious webpage or opening a compromised file, putting users at significant risk.

Affected Version(s)

NetCDF-C dbe0cbb9ff3f706009cf4ee011adf3e58d8a81c1

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.