CVE-2025-46599 affects CNCF K3s versions prior to 1.32.4-rc1+k3s1, where an unintended kubelet configuration change can set ReadOnlyPort to 10255. This misconfiguration, particularly in default online installations, may expose credentials through unauthenticated access to this port. This vulnerability is rated Medium severity (CVSS 6.8), indicating a network-based attack with high complexity, requiring no user interaction or privileges. A successful exploit could lead to high confidentiality impact by exposing sensitive information. Currently, there is no evidence of active exploitation, nor is exploit code available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.32, < 1.32.4-rc1+k3sCPE match | cpe:2.3:a:k3s:k3s:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.