CVE-2025-71261highCWE-295

CVE-2025-71261: high-severity vulnerability in SUSE Harvester

Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS

Published

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.6epss 0.2%
exploitation probability
0.2%top 90% of all CVEs
observed exploitation
nono source reports it
An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it to bypass TLS as a security control.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Affected products
SUSE · Harvester