CVE-2025-60892 (CNNVD-202511-079)
中文标题:
Raspberry Pi Imager 安全漏洞
英文标题:
An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. T...
漏洞描述
中文描述:
Raspberry Pi Imager是Raspberry Pi开源的一款工具软件。 Raspberry Pi Imager 1.9.6版本存在安全漏洞,该漏洞源于公钥认证设置错误地将本地id_rsa.pub密钥重新添加到Raspberry Pi的authorized_keys文件中,可能导致攻击者使用非预期密钥登录设备。
英文描述:
An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting unintentionally re-adds a user's id_rsa.pub key from their local Windows machine to the authorized_keys file on the Raspberry Pi, even after the user explicitly deletes the key from the user interface. This creates an unintended attack surface, as it could allow an attacker to use a different key than the intended one to login to the device.
CWE类型:
标签:
受影响产品
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.1 (adp)
MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-60892 |
2025-11-11 15:23:33 | 2025-11-11 07:40:48 |
| NVD | nvd_CVE-2025-60892 |
2025-11-11 15:01:07 | 2025-11-11 07:48:34 |
| CNNVD | cnnvd_CNNVD-202511-079 |
2025-11-11 15:13:01 | 2025-11-11 08:00:21 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202511-079
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']