CVE-2025-7342
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-17

Last updated on: 2025-11-04

Assigner: Kubernetes

Description
A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows image build process when using the Nutanix or VMware OVA providers. These credentials, which allow root access, are disabled at the conclusion of the build. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project and the vulnerability was exploited during the build process, which requires an attacker to access the build VM and modify the image while the build is in progress.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-17
Last Modified
2025-11-04
Generated
2026-05-07
AI Q&A
2025-08-18
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
kubernetes image_builder 0.1.44
vmware ova *
kubernetes image_builder 0.1.45
nutanix ova *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability occurs in the Kubernetes Image Builder where default credentials are enabled during the image build process. Specifically, virtual machine images built using the Nutanix or OVA provider do not disable these default credentials. As a result, nodes using these images may be accessed using these default credentials, potentially allowing an attacker to gain root access.


How can this vulnerability impact me? :

If your Kubernetes cluster has Windows nodes that use VM images created via the Image Builder project with the Nutanix or OVA provider, an attacker could use the default credentials to gain root access to those nodes. This could lead to full control over the affected nodes, compromising confidentiality, integrity, and availability of your systems.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart