THREAT OPS › Threat News › [NVD] CVE-2025-2241 (HIGH 8.2) — A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision ob
[NVD] CVE-2025-2241 (HIGH 8.2) — A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision ob
CVE-2025-2241 CVSS: 8.2 HIGH Published: 2025-03-17T17:15:40.393
A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2025-2241cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-2241