CVE-2025-46599

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 1188

Summary

CVE-2025-46599 is a vulnerability affecting the K3s 1.32 version of the Kubernetes kubelet, where the unintentional configuration change results in ReadOnlyPort being set to 10255. In certain circumstances, such as in default online installations, this can lead to unauthenticated access to the port and potential exposure of credentials. The issue was found before the release of version 1.32.4-rc1+k3s1 as a fix.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share