CVE-2025-62877
published 2026-01-08CVE-2025-62877: Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password if they are using the 1.5.x or 1.6.x interactive…
PriorityP359critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.47%
37.7th percentile
Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along with the Harvester configuration setup.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | harvester_harvester-installer | 1.5.0 – 1.5.2 | — |
| github.com | harvester_harvester-installer | >= 1.5.0 | — |
| github.com | harvester_harvester-installer | 1.6.0 – 1.6.1 | — |
| github.com | harvester_harvester-installer | >= 1.6.0 | — |
| suse | harvester | — | — |
| suse | harvester | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive Installer in github.com/harvester/harvester-installer
osv·2026-01-12
CVE-2025-62877 Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive Installer in github.com/harvester/harvester-installer
Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive Installer in github.com/harvester/harvester-installer
Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive Installer in github.com/harvester/harvester-installer
OSV
Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive Installer
osv·2026-01-05
CVE-2025-62877 [CRITICAL] Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive Installer
Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive Installer
### Impact
Projects using the SUSE Virtualization (Harvester) environment are vulnerable to this exploit if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the [PXE boot mechanism](https://docs.harvesterhci.io/v1.7/install/pxe-boot-install/) is utilized along with the [Harvester configuration](https://docs.harvesterhci. io/v1.7/install/harvester-configuration) setup.
A critical vulnerability has been identified within the SUSE Virtualization interactive installer. This vulnerability allows an attacker to gain unauthorized network access to the host via a remote shell (SSH).
The S
GHSA
Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive Installer
ghsa·2026-01-05
CVE-2025-62877 [CRITICAL] CWE-1188 Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive Installer
Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive Installer
### Impact
Projects using the SUSE Virtualization (Harvester) environment are vulnerable to this exploit if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the [PXE boot mechanism](https://docs.harvesterhci.io/v1.7/install/pxe-boot-install/) is utilized along with the [Harvester configuration](https://docs.harvesterhci. io/v1.7/install/harvester-configuration) setup.
A critical vulnerability has been identified within the SUSE Virtualization interactive installer. This vulnerability allows an attacker to gain unauthorized network access to the host via a remote shell (SSH).
The S
No detection rules found.
No public exploits indexed.
2026-01-08
Published