CVE-2025-10725
A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example as a data scientist using a standard Jupyter notebook, can escalate their privileges to a full cluster administrator. This allows for the complete compromise of the cluster's confidentiality, integrity, and availability. The attacker can steal sensitive data, disrupt all services, and take control of the underlying infrastructure, leading to a total breach of the platform and all applications hosted on it.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 9.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.70%
- Percentil entre todas las CVEs puntuadas: 52
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement60 %
Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-266
Referencias
- https://access.redhat.com/errata/RHSA-2025:16981
- https://access.redhat.com/errata/RHSA-2025:16982
- https://access.redhat.com/errata/RHSA-2025:16983
- https://access.redhat.com/errata/RHSA-2025:16984
- https://access.redhat.com/errata/RHSA-2025:17501
- https://access.redhat.com/security/cve/CVE-2025-10725
- https://bugzilla.redhat.com/show_bug.cgi?id=2396641
- https://github.com/opendatahub-io/opendatahub-operator/commit/070057ebd0882be0e397bee1daa18c36374a03c0
- https://github.com/opendatahub-io/opendatahub-operator/pull/2571
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-10725",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-10725",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-09-30T18:32:34.716566Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.9,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 3.1
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "opendatahub-io",
"product": "opendatahub-operator",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "3.0.0",
"versionType": "semver"
}
],
"packageName": "opendatahub-operator",
"collectionURL": "https://github.com/opendatahub-io/opendatahub-operator",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.16::el8"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.16",
"versions": [
{
"status": "unaffected",
"version": "sha256:cebc8815e03b772343b15d0a7dce8fad6fcc71dd437d871db5a3691472350803",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-rhel8-operator",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.19::el8"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.19",
"versions": [
{
"status": "unaffected",
"version": "sha256:43a8904396e55074ffb1afcfcd8fe6db0edcbc918a8ff8301b6b0920aea7eabf",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-rhel8-operator",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.21::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.21",
"versions": [
{
"status": "unaffected",
"version": "sha256:db339d2d4f86af4efa695ef193d19e26b25fec80017fa2780833a4cd944e383b",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-rhel9-operator",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.22::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.22",
"versions": [
{
"status": "unaffected",
"version": "sha256:dccc7c6cf920da7ffeadbad42f5727f2d58d54ceef399ac98441345d06ff10c4",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-rhel9-operator",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.24::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.24",
"versions": [
{
"status": "unaffected",
"version": "sha256:12c1d1066e75951aad1d333bcbc1675ba7a795b57744294c23decec1655709c7",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-rhel9-operator",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
}
]
}
],
"published": "2025-09-30T18:15:47.900",
"references": [
{
"url": "https://access.redhat.com/errata/RHSA-2025:16981",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2025:16982",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2025:16983",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2025:16984",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2025:17501",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2025-10725",
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2396641",
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/opendatahub-io/opendatahub-operator/commit/070057ebd0882be0e397bee1daa18c36374a03c0",
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/opendatahub-io/opendatahub-operator/pull/2571",
"source": "secalert@redhat.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-266"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example as a data scientist using a standard Jupyter notebook, can escalate their privileges to a full cluster administrator. This allows for the complete compromise of the cluster's confidentiality, integrity, and availability. The attacker can steal sensitive data, disrupt all services, and take control of the underlying infrastructure, leading to a total breach of the platform and all applications hosted on it."
},
{
"lang": "es",
"value": "Se encontró una falla en el Servicio de IA de Red Hat Openshift. Un atacante de bajo privilegio con acceso a una cuenta autenticada, por ejemplo como científico de datos usando un cuaderno Jupyter estándar, puede escalar sus privilegios a un administrador de clúster completo. Esto permite el compromiso completo de la confidencialidad, integridad y disponibilidad del clúster. El atacante puede robar datos sensibles, interrumpir todos los servicios y tomar control de la infraestructura subyacente, lo que lleva a una brecha total de la plataforma y todas las aplicaciones alojadas en ella."
}
],
"lastModified": "2026-06-17T08:28:50.817",
"sourceIdentifier": "secalert@redhat.com"
}