CVE-2025-15323 Details
Description
Tanium addressed an improper certificate validation vulnerability in Tanium Appliance.
An improper certificate validation vulnerability has been addressed in Tanium Appliance. This vulnerability could enable an unauthenticated, network-based attacker to view or modify log data when a remote syslog destination is configured to use TLS. The issue is present in Tanium Appliance versions prior to Update 24 (v1.8.3.0199) in the 2024H1 release, prior to Update 12 (v1.8.4.0205) in the 2024H2 release, and prior to Update 6 (v1.8.5.0236) in the 2025H1 release.
Users can update to Tanium Appliance version 1.8.3.0199 or later for the 2024H1 release, version 1.8.4.0205 or later for the 2024H2 release, and version 1.8.5.0236 or later for the 2025H1 release.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.tanium.com/TAN-2025-031 | Tanium | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | Tanium |
Affected Products
| Product | Versions |
|---|---|
| tanium tanos | >= 1.8.3, < 1.8.3.0199 >= 1.8.4, < 1.8.4.0205 >= 1.8.5, < 1.8.5.0236 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Tanium |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 10, 2026 | Reanalysis | [email protected] |
| Feb 10, 2026 | Initial Analysis | [email protected] |
| Feb 5, 2026 | New CVE Received | Tanium |