PT-2025-44765 · Raspberry Pi Foundation · Raspberry Pi Imager
CVE-2025-60892
·
Publicado
2025-11-03
·
Atualizado
2025-11-03
CVSS v3.1
6.8
Média
| Vetor | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Raspberry Pi Imager version 1.9.6
Description
An issue exists in the OS customization feature of Raspberry Pi Imager. The 'public-key authentication' setting unintentionally re-adds a user's
id rsa.pub key from their local Windows machine to the authorized keys file on the Raspberry Pi, even after the user deletes the key through the user interface. This could allow an attacker to use a different key to login to the device, creating an unintended attack surface.Recommendations
Update to a newer version of Raspberry Pi Imager that contains a fix for this vulnerability.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Raspberry Pi Imager