Impact
This flaw in cockpit-machines allows a local attacker to view plaintext password values that are passed on the command line when a virtual machine is created or installed. By inspecting the running process arguments, the attacker can learn VM credentials that are otherwise meant to remain secret, leading to confidentiality loss of the managed virtual machines.
Affected Systems
Affected products include Red Hat Enterprise Linux 10 and Red Hat Enterprise Linux 9, as listed by the vendor. The specific component impacted is the cockpit‑machines service; any installation of the service on these operating systems is susceptible.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity vulnerability that is not critical but warrants attention. The EPSS score is not available, so no concrete exploitation likelihood is reported. The vulnerability requires only local user access, so any user with the ability to launch VM creation or installation processes could exploit the flaw. It is not listed in the CISA KEV catalog, meaning there have been no known or widespread exploitation reports as of the data provided.
OpenCVE Enrichment