CVE-2025-14551 is a credential disclosure vulnerability in Ubuntu's Subiquity installer version 24.04.4 that exposes sensitive user information during the crash reporting process. When an installation failure occurs and a user submits a bug report to Launchpad, the application may inadvertently include plaintext credentials such as Wi-Fi passwords in the attached diagnostic logs. The vulnerability carries a HIGH severity rating with a CVSS score of 8.1, requiring network access and low privileges but imposing no interaction requirements. The attack vector is network-based, the attack complexity is low, and the confidentiality impact is high, potentially exposing sensitive authentication credentials to unauthorized parties. Additionally, the vulnerability poses availability concerns in the scope of affected systems. While CVE-2025-14551 does not currently appear on the Known Exploited Vulnerabilities (KEV) catalog, it has been marked as active on the Hot List, indicating community attention and relevant threat activity. The EPSS score of 0.00044 suggests relatively low probability of exploitation compared to the broader CVE landscape, though the credential disclosure nature of this issue warrants prompt patching to prevent potential unauthorized access to user networks and systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
24.04.4CPE matchmatch criteria | cpe:2.3:a:canonical:ubuntu_subiquity:24.04.4:*:*:*:*:*:*:* | ||
>= 0, <= 24.04.4CPE match | cpe:2.3:o:canonical:ubuntu:*:*:*:*:*:*:*:* | ||
>= 0, <= 25.04CPE match | cpe:2.3:o:canonical:ubuntu:*:*:*:*:*:*:*:* | ||
>= 0, <= 25.10CPE match | cpe:2.3:o:canonical:ubuntu:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.