« Volver al listado

CVE-2025-62878

Estado: AplazadaCrítica (9.9)—

A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Requiere PR:L y AV:N: explotación de servicio remoto (T1210). Impactos: manipulación de archivos sensibles (T1565.001), lectura de datos no autorizados (T1005) y potencial escalada de privilegios (T1068) por acceso a directorios del host.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-62878",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-62878",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-02-26T04:55:51.167071Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "meissner@suse.de",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.9,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.1
      }
    ]
  },
  "affected": [
    {
      "source": "meissner@suse.de",
      "affectedData": [
        {
          "vendor": "SUSE",
          "product": "Rancher",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.0.34",
              "versionType": "semver"
            }
          ],
          "packageName": "github.com/rancher/local-path-provisioner",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-02-25T11:16:01.747",
  "references": [
    {
      "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-62878",
      "source": "meissner@suse.de"
    },
    {
      "url": "https://github.com/advisories/GHSA-jr3w-9vfr-c746",
      "source": "meissner@suse.de"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "meissner@suse.de",
      "description": [
        {
          "lang": "en",
          "value": "CWE-23"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories."
    },
    {
      "lang": "es",
      "value": "Un usuario malintencionado puede manipular el parámetro parameters.pathPattern para crear PersistentVolumes en ubicaciones arbitrarias en el nodo anfitrión, potencialmente sobrescribiendo archivos sensibles u obteniendo acceso a directorios no deseados."
    }
  ],
  "lastModified": "2026-06-17T09:52:34.820",
  "sourceIdentifier": "meissner@suse.de"
}