CVE-2021-32001
Estado: ModificadaMedia (6.5)—
K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the cluster's confidential keying material (cluster certificate authority private keys, secrets encryption configuration passphrase, etc.) and decrypt it, without having to know the token value. This issue affects: SUSE Rancher K3s version v1.19.12+k3s1, v1.20.8+k3s1, v1.21.2+k3s1 and prior versions; RKE2 version v1.19.12+rke2r1, v1.20.8+rke2r1, v1.21.2+rke2r1 and prior versions.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.30%
- Percentil entre todas las CVEs puntuadas: 21
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-311
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-32001",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "meissner@suse.de",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "meissner@suse.de",
"affectedData": [
{
"vendor": "SUSE",
"product": "Rancher",
"versions": [
{
"status": "affected",
"version": "K3s",
"versionType": "custom",
"lessThanOrEqual": "v1.19.12+k3s1, v1.20.8+k3s1, v1.21.2+k3s1"
}
]
},
{
"vendor": "SUSE",
"product": "Rancher",
"versions": [
{
"status": "affected",
"version": "RKE2",
"versionType": "custom",
"lessThanOrEqual": "v1.19.12+rke2r1, v1.20.8+rke2r1, v1.21.2+rke2r1"
}
]
}
]
}
],
"published": "2021-07-28T10:15:08.327",
"references": [
{
"url": "https://bugzilla.suse.com/show_bug.cgi?id=1188453",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "meissner@suse.de"
},
{
"url": "https://bugzilla.suse.com/show_bug.cgi?id=1188453",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "meissner@suse.de",
"description": [
{
"lang": "en",
"value": "CWE-311"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the cluster's confidential keying material (cluster certificate authority private keys, secrets encryption configuration passphrase, etc.) and decrypt it, without having to know the token value. This issue affects: SUSE Rancher K3s version v1.19.12+k3s1, v1.20.8+k3s1, v1.21.2+k3s1 and prior versions; RKE2 version v1.19.12+rke2r1, v1.20.8+rke2r1, v1.21.2+rke2r1 and prior versions."
},
{
"lang": "es",
"value": "K3s en SUSE Rancher permite a cualquier usuario con acceso directo al almacén de datos, o a una copia de seguridad del almacén de datos, extraer el material de clave confidencial del clúster (claves privadas de la autoridad de certificación del clúster, frase de contraseña de configuración de cifrado de secretos, etc.) y descifrarlo, sin tener que conocer el valor del token. Este problema afecta a: SUSE Rancher K3s versión v1.19.12+k3s1, v1.20.8+k3s1, v1.21.2+k3s1 y versiones anteriores; RKE2 versión v1.19.12+rke2r1, v1.20.8+rke2r1, v1.21.2+rke2r1 y versiones anteriores"
}
],
"lastModified": "2026-06-17T03:52:39.283",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:suse:rancher_k3s:1.19.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F01F797-DFE0-4B12-96BF-C92EED0CD7B0"
},
{
"criteria": "cpe:2.3:a:suse:rancher_k3s:1.20.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "438C56A6-DC6C-430D-91C9-7A392CB15935"
},
{
"criteria": "cpe:2.3:a:suse:rancher_k3s:1.21.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E087A392-429D-4157-927D-D5A12C301F59"
},
{
"criteria": "cpe:2.3:a:suse:rancher_rke2:1.19.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "116A6CD7-3027-44F6-80A8-1CBD95547DA9"
},
{
"criteria": "cpe:2.3:a:suse:rancher_rke2:1.20.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "03D93121-9542-43C3-AAA3-82B406C329E5"
},
{
"criteria": "cpe:2.3:a:suse:rancher_rke2:1.21.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F878C56D-62E2-4132-9F06-FB22365995E3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "meissner@suse.de"
}