Suse Harvester vulnerabilities
3 known vulnerabilities affecting suse/harvester.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1LOW1
Vulnerabilities
Page 1 of 1
CVE-2025-62877P3CRITICALCVSS 9.8v1.6.0v1.5.02026-01-08
CVE-2025-62877 [CRITICAL] CWE-1188 CVE-2025-62877: Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login p
Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along with the Harvester configuration
nvd
CVE-2025-71261P3HIGHCVSS 8.6fixed in 1.82026-06-16
CVE-2025-71261 [HIGH] CWE-295 CVE-2025-71261: An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE H
An attacker with network-level access between the SUSE Virtualization
and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it
to bypass TLS as a security control.
nvd
CVE-2025-67860P4LOWCVSS 3.8≥ 4.0, < 4.0722026-02-25
CVE-2025-67860 [LOW] CWE-522 CVE-2025-67860: A vulnerability has been identified in the NeuVector scanner where the scanner process accepts regis
A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller credentials as command-line arguments, potentially exposing sensitive credentials to local users.
nvd