CVE-2025-2241
Last modified
CVE-2025-2241 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-2241?
How severe is CVE-2025-2241?
How do I fix CVE-2025-2241?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-22404In avct_lcb_msg_ind of avct_lcb_act.cc, there is a possible …8.4
- CVE-2025-22405In multiple locations, there is a possible way to execute ar…8.4
- CVE-2025-22406In bnepu_check_send_packet of bnep_utils.cc, there is a poss…8.4
- CVE-2025-22407In hidd_check_config_done of hidd_conn.cc, there is a possib…5.5
- CVE-2025-22408In rfc_check_send_cmd of rfc_utils.cc, there is a possible w…9.8
- CVE-2025-22409In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible…8.4
- CVE-2025-22410In multiple locations, there is a possible way to execute ar…8.4
- CVE-2025-22411In process_service_attr_rsp of sdp_discovery.cc, there is a …8.8
- CVE-2025-22412In multiple functions of sdp_server.cc, there is a possible …8.8
- CVE-2025-22413In multiple functions of hyp-main.c, there is a possible pri…4
- CVE-2025-22414In FrpBypassAlertActivity of FrpBypassAlertActivity.java, th…7.8
- CVE-2025-22415In android_app of Android.bp, there is a possible way to lau…4
Are you affected by CVE-2025-2241?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
