# CVE-2024-1725

## Summary

- **CVE ID:** CVE-2024-1725
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-501
- **Published:** Mar 7, 2024
- **Last Modified:** Mar 13, 2026

## Description

A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.

## Affected Products

- Unknown product (a61f36c42700f54352919318ed806d1ae2d716f4)
- Red Hat — Red Hat OpenShift Container Platform 4.13 (v4.13.0-202404200313.p0.g9d909f7.assembly.stream.el8)
- Red Hat — Red Hat OpenShift Container Platform 4.14 (v4.14.0-202404161544.p0.g48fafc4.assembly.stream.el8)
- Red Hat — Red Hat OpenShift Container Platform 4.15 (v4.15.0-202403220332.p0.gd3bdbce.assembly.stream.el8)

## References

- [CNA](https://access.redhat.com/errata/RHSA-2024:1559)
- [CNA](https://access.redhat.com/errata/RHSA-2024:1891)
- [CNA](https://access.redhat.com/errata/RHSA-2024:2047)
- [CNA](https://access.redhat.com/security/cve/CVE-2024-1725)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2265398)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.63%
- **EPSS Percentile:** 48.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._