CVE-2025-2903 describes a high-severity vulnerability in Google Cloud Platform's OS Login feature, allowing an attacker with specific knowledge of user account creation during VM deployment to gain SSH access and command-line control. This physical attack vector requires high privileges and low attack complexity, enabling the attacker to access sensitive data, install malware, and disrupt VM functionality. Despite its significant impact, there is currently no known active exploitation, public exploit code, or notable community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Perforce | Delphix | >= 14.0.0.0, <= 2025.2.0.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.