CVE-2025-62877
Last modified
CVE-2025-62877 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along with the Harvester configuration setup.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along with the Harvester configuration setup.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-62877?
How severe is CVE-2025-62877?
How do I fix CVE-2025-62877?
Are you affected by CVE-2025-62877?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
