CVE-2025-70342
MEDIUM 6.6EPSS 0.2%
erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.json. This allows an unauthenticated attacker to intercept admin credentials entered during reinstall/erase operations via creating a named pipe.
- CVSS v3.1
- 6.6 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N - EPSS
- 0.24% chance of exploitation in the next 30 days, 15th percentile
- Published
- 2026-03-04