External risk intelligence

SUSE Virtualization Harvester Installer Exposes Default SSH Password

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-62877

The vulnerability exists specifically within the interactive installer process used during the creation of a new cluster or addition of new hosts. This is a deployment-time or provisioning-time activity, not a service-level exposure, and is typically performed within a secure, controlled, or isolated administrative environment rather than being exposed to the public internet.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Projects utilizing SUSE Virtualization (Harvester) may inadvertently expose the operating system's default SSH password during interactive installation. This occurs when creating new clusters or adding hosts to existing ones, but not when using the PXE boot mechanism with Harvester's configuration setup.

  • Default passwords may be exposed during installation.
  • This is a setup issue, not a service exposure.
  • Confirm if interactive installers were used in your environment.

Attack Path

How an attacker could exploit the issue

An attacker could potentially gain access to the default SSH password during the installation or expansion of SUSE Virtualization (Harvester) environments, but only if the interactive installer is used and the PXE boot mechanism is not. This exposure could allow an attacker to compromise the system.

  • Default password exposed during installation.
  • Interactive installer and no PXE boot required.
  • Risk of unauthorized system access.

Live Threat

Current exploitation, exposure, and threat context

SUSE Virtualization (Harvester) environments that use the interactive installer to set up new clusters or add hosts may expose the default OS SSH login password. This exposure is prevented when using the PXE boot mechanism with Harvester's configuration setup.

  • Default SSH password could be exposed.
  • Via interactive installer during cluster setup.
  • Unauthorized access to the operating system.

Operational Fix

Recommended remediation, mitigation, and detection steps

The SUSE Virtualization (Harvester) environment is affected when using the interactive installer for cluster creation or host additions, potentially exposing default SSH login passwords. This issue is mitigated if the PXE boot mechanism is used for Harvester configuration. Owners of the Harvester platform and infrastructure teams should prioritize identifying affected deployments, confirming business criticality and external reachability, and then planning remediation based on the identified risk.

  • Platform owners should manage this issue.
  • Verify affected cluster creation methods.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is SUSE Virtualization (Harvester)?

Harvester is an open-source, enterprise-grade virtualization platform built on Kubernetes. It is designed to run virtual machines alongside containerized workloads, providing a unified infrastructure solution for managing compute and storage resources in data center environments.

What does CWE-1188 mean for CVE-2025-62877?

CWE-1188 refers to the use of default or predictable credentials. In the context of this CVE, it means the software's interactive installer may fail to properly secure the operating system's default SSH password during the initial setup or cluster expansion process.

Does my existing cluster configuration trigger this bug?

The issue is limited to the provisioning phase. It specifically affects the interactive installer when creating a new cluster or adding new hosts. If you used the PXE boot mechanism to deploy your Harvester environment, your system is not affected by this vulnerability.

Is my Harvester environment at risk?

According to Halo Surface Signal, this risk is very unlikely because the vulnerability is tied to a one-time provisioning action, not a continuous service-level exposure. Since this activity typically occurs within a secure, isolated administrative network, it is rarely exposed to the public internet.

How should I respond to this vulnerability?

First, review your infrastructure logs or deployment documentation to determine if the interactive installer was used for your Harvester nodes. If it was, treat the system as potentially compromised, rotate the OS SSH credentials immediately, and consult official guidance for secure deployment patterns.

References