Back to overview

CVE-2025-62877

CRITICAL
9.8
CVSS 3.1
Description
Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along with the Harvester configuration setup.

Metadata

CVE ID
CVE-2025-62877
State
PUBLISHED
Assigner
suse
Reserved
2025-10-24 10:34 UTC
Published
2026-01-08 12:29 UTC
Last updated
2026-01-08 14:43 UTC
Primary CWE
CWE-1188
CWE-1188: Initialization of a Resource with an Insecure Defa…
Vendor / Product
SUSE / harvester
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
SUSE harvester 1.6.0, 1.5.0
Weakness (CWE)
CWESourceDescription
CWE-1188 cna CWE-1188: Initialization of a Resource with an Insecure Default
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview