CVE 7.5 HIGH

VM images built with Kubernetes Image Builder Nutanix or OVA providers use default credentials for Windows images if user did not override_CVE-2025-7342

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the image build process. Additionally, virtual machine images built using the Nutanix or the OVA provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their Windows nodes use VM images created via the Image Builder project with its Nutanix or OVA provider.

Basic Information

ID CVE-2025-7342
Source kubernetes
Published Aug 17, 2025 at 23:03

Affected Product

Vendor Kubernetes
Product Image Builder
Affected Versions Kubernetes Image Builder 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.