9.9
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
A vulnerability was identified in NeuVector, where the enforcer used environment variables CLUSTER_RPC_PORT and CLUSTER_LAN_PORT to generate a command to be executed via popen, without first sanitising their values.
The entry process of the enforcer container is the monitor
process. When the enforcer container stops, the monitor process checks
whether the consul subprocess has exited. To perform this check, the
monitor process uses the popen function to execute a shell command that determines whether the ports used by the consul subprocess are still active.
The values of environment variables CLUSTER_RPC_PORT and CLUSTER_LAN_PORT
are used directly to compose shell commands via popen without
validation or sanitization. This behavior could allow a malicious user
to inject malicious commands through these variables within the enforcer
container.
The entry process of the enforcer container is the monitor
process. When the enforcer container stops, the monitor process checks
whether the consul subprocess has exited. To perform this check, the
monitor process uses the popen function to execute a shell command that determines whether the ports used by the consul subprocess are still active.
The values of environment variables CLUSTER_RPC_PORT and CLUSTER_LAN_PORT
are used directly to compose shell commands via popen without
validation or sanitization. This behavior could allow a malicious user
to inject malicious commands through these variables within the enforcer
container.
AI Analysis
NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow due to unsanitized environment variables used in shell commands
Basic Information
ID
CVE-2025-54469
Source
suse
Published
Oct 30, 2025 at 09:41
Modified
Oct 30, 2025 at 14:00
Affected Product
Vendor
SUSE
Product
neuvector
Version
5.3.0, 5.4.0, 0.0.0-20230727023453-1c4957d53911
Affected Versions
SUSE neuvector 5.3.0
SUSE neuvector 5.4.0
SUSE neuvector 0.0.0-20230727023453-1c4957d53911
SUSE neuvector 5.4.0
SUSE neuvector 0.0.0-20230727023453-1c4957d53911
CWE Classification
AI Assessment
AI Score
9.9 / 10
AI Severity
Critical
Vendor
NeuVector
Product
NeuVector Enforcer
Version
5.3.0, 5.4.0, 0.0.0-20230727023453-1c4957d53911