Horizon Alert
Summary of the vulnerability and why it matters
Projects utilizing SUSE Virtualization (Harvester) may inadvertently expose the operating system's default SSH password during interactive installation. This occurs when creating new clusters or adding hosts to existing ones, but not when using the PXE boot mechanism with Harvester's configuration setup.
- Default passwords may be exposed during installation.
- This is a setup issue, not a service exposure.
- Confirm if interactive installers were used in your environment.
Attack Path
How an attacker could exploit the issue
An attacker could potentially gain access to the default SSH password during the installation or expansion of SUSE Virtualization (Harvester) environments, but only if the interactive installer is used and the PXE boot mechanism is not. This exposure could allow an attacker to compromise the system.
- Default password exposed during installation.
- Interactive installer and no PXE boot required.
- Risk of unauthorized system access.
Live Threat
Current exploitation, exposure, and threat context
SUSE Virtualization (Harvester) environments that use the interactive installer to set up new clusters or add hosts may expose the default OS SSH login password. This exposure is prevented when using the PXE boot mechanism with Harvester's configuration setup.
- Default SSH password could be exposed.
- Via interactive installer during cluster setup.
- Unauthorized access to the operating system.
Operational Fix
Recommended remediation, mitigation, and detection steps
The SUSE Virtualization (Harvester) environment is affected when using the interactive installer for cluster creation or host additions, potentially exposing default SSH login passwords. This issue is mitigated if the PXE boot mechanism is used for Harvester configuration. Owners of the Harvester platform and infrastructure teams should prioritize identifying affected deployments, confirming business criticality and external reachability, and then planning remediation based on the identified risk.
- Platform owners should manage this issue.
- Verify affected cluster creation methods.
- Plan remediation based on risk.