Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-2903


An attacker with knowledge of creating user accounts during VM deployment on Google Cloud Platform (GCP) using the OS Login feature, can login via SSH gaining command-line control of the operating system. This allows an attacker to gain access to sensitive data stored on the VM, install malicious software, and disrupt or disable the functionality of the VM.


Published

2025-04-17T07:15:42.520

Last Modified

2025-04-17T20:21:48.243

Status

Awaiting Analysis

Source

[email protected]

Severity

-

Weaknesses
  • Type: Secondary
    CWE-267
    CWE-268

Affected Vendors & Products

-


References