CVE-2025-46599
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 1188
Summary
CVE-2025-46599 is a vulnerability affecting the K3s 1.32 version of the Kubernetes kubelet, where the unintentional configuration change results in ReadOnlyPort being set to 10255. In certain circumstances, such as in default online installations, this can lead to unauthenticated access to the port and potential exposure of credentials. The issue was found before the release of version 1.32.4-rc1+k3s1 as a fix.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- K3s
Affected Vendors
- K3s