CVE-2025-67860 is a low-severity vulnerability in the NeuVector scanner where sensitive registry and controller credentials can be exposed to local users due to their acceptance as command-line arguments. This local attack vector (AV:L) has low attack complexity (AC:L) and requires low privileges (PR:L), potentially leading to limited confidentiality impact (C:L) with no integrity or availability impact. There is no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code. While community discussion and media coverage are minimal, a security update for govulncheck-vulndb has been released by SUSE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SUSE | Harvester | >= 4.0, < 4.072CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.