Impact
KubeEdge CloudCore versions up to 1.23.1 allow unauthenticated HTTPS requests to the node task status reporting endpoint. The endpoint accepts status updates for upgrade jobs, and an attacker can craft messages that mark an upgrade as succeeded or failed without a real upgrade occurring. This misleads the control plane into believing the node is in a different state, potentially blocking future upgrades or causing the control plane to perform actions based on false status information. The vulnerability arises from a lack of authentication (CWE-306).
Affected Systems
KubeEdge (Linux Foundation) CloudCore, version 1.23.1; the affected product is the CloudCore component that handles node task status reporting.
Risk and Exploitability
The CVSS score of 8.8 indicates a high impact vulnerability. EPSS data is not available, leaving the exploitation probability uncertain, yet the lack of authentication means the endpoint can be reached by any actor with network connectivity to port 10002. The vulnerability is not yet listed in the CISA KEV catalog, implying no confirmed exploits, but the attack vector is remote network access to the device, allowing any uncontrolled user to send status updates.
OpenCVE Enrichment