{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-14T22:12:32.424","vulnerabilities":[{"cve":{"id":"CVE-2025-2903","sourceIdentifier":"security@puppet.com","published":"2025-04-17T07:15:42.520","lastModified":"2025-04-17T20:21:48.243","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"An attacker with knowledge of creating user accounts during VM deployment on Google Cloud Platform (GCP) using the OS Login feature, can login via SSH gaining command-line control of the operating system. This allows an attacker to gain access to sensitive data stored on the VM, install malicious software, and disrupt or disable the functionality of the VM."},{"lang":"es","value":"Un atacante con conocimientos sobre la creación de cuentas de usuario durante la implementación de una máquina virtual en Google Cloud Platform (GCP) mediante la función de inicio de sesión del sistema operativo, puede iniciar sesión por SSH y obtener el control del sistema operativo desde la línea de comandos. Esto le permite acceder a datos confidenciales almacenados en la máquina virtual, instalar software malicioso e interrumpir o deshabilitar su funcionalidad."}],"metrics":{"cvssMetricV40":[{"source":"security@puppet.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0\/AV:P\/AC:L\/AT:N\/PR:H\/UI:N\/VC:H\/VI:H\/VA:N\/SC:H\/SI:H\/SA:H\/E:X\/CR:X\/IR:X\/AR:X\/MAV:X\/MAC:X\/MAT:X\/MPR:X\/MUI:X\/MVC:X\/MVI:X\/MVA:X\/MSC:X\/MSI:X\/MSA:X\/S:X\/AU:X\/R:X\/V:X\/RE:X\/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"PHYSICAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security@puppet.com","type":"Secondary","description":[{"lang":"en","value":"CWE-267"},{"lang":"en","value":"CWE-268"}]}],"references":[{"url":"https:\/\/portal.perforce.com\/s\/detail\/a91PA000001Sed3YAC","source":"security@puppet.com"}]}}]}