CVE-2025-71261: high-severity vulnerability in SUSE Harvester
Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.6epss 0.2%
exploitation probability
0.2%top 90% of all CVEs
observed exploitation
nono source reports it
An attacker with network-level access between the SUSE Virtualization
and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it
to bypass TLS as a security control.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Affected products
SUSE · Harvester