← volver
CVE-2025-62877

Harvest may expose OS default ssh login password via SUSE Virtualization Interactive Installer

CVSS 9.8 CRITICALEPSS 0.5%CWE-1188
Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along with the Harvester configuration setup.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
SUSE · harvester

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →