CVE-2025-67601
Estado: AnalizadaMedia (4.8)—
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
- Puntuación base: 4.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 4
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-295
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-67601",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-67601",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-02-26T04:55:52.856025Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "meissner@suse.de",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.3,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "meissner@suse.de",
"affectedData": [
{
"vendor": "SUSE",
"product": "rancher",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "0.0.0-20260129092249-bb0625fd1896",
"versionType": "semver"
},
{
"status": "affected",
"version": "2.13.0",
"lessThan": "2.13.2",
"versionType": "semver"
},
{
"status": "affected",
"version": "2.12.0",
"lessThan": "2.12.6",
"versionType": "semver"
},
{
"status": "affected",
"version": "2.11.0",
"lessThan": "2.11.10",
"versionType": "semver"
},
{
"status": "affected",
"version": "2.10.0",
"lessThan": "2.10.11",
"versionType": "semver"
}
],
"packageName": "github.com/rancher/rancher",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-02-25T11:16:02.643",
"references": [
{
"url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-67601",
"tags": [
"Issue Tracking"
],
"source": "meissner@suse.de"
},
{
"url": "https://github.com/rancher/rancher/security/advisories/GHSA-mc24-7m59-4q5p",
"tags": [
"Vendor Advisory"
],
"source": "meissner@suse.de"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "meissner@suse.de",
"description": [
{
"lang": "en",
"value": "CWE-295"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts."
},
{
"lang": "es",
"value": "Una vulnerabilidad ha sido identificada dentro de Rancher Manager, donde el uso de certificados CA autofirmados y pasar la bandera -skip-verify al comando de inicio de sesión de Rancher CLI sin pasar también la bandera –cacert resulta en que la CLI intenta obtener certificados CA almacenados en la configuración 'cacerts' de Rancher."
}
],
"lastModified": "2026-06-17T09:57:54.763",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8434BB27-8099-4685-9FE5-C3E4FF565E79",
"versionEndExcluding": "2.10.11",
"versionStartIncluding": "2.10.0"
},
{
"criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B7549C0-3315-469C-A43F-E8B7095E570D",
"versionEndExcluding": "2.11.10",
"versionStartIncluding": "2.11.0"
},
{
"criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81C70333-B5C6-4DAB-92B0-0FA49ED9CBE7",
"versionEndExcluding": "2.12.6",
"versionStartIncluding": "2.12.0"
},
{
"criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FDEACDC9-6A42-488C-AD8B-46E1B26CA943",
"versionEndExcluding": "2.13.2",
"versionStartIncluding": "2.13.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "meissner@suse.de"
}