8.6
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Description
This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVector sends anonymous telemetry data to the telemetry server.
In affected versions, NeuVector does not enforce TLS
certificate verification when transmitting anonymous cluster data to the
telemetry server. As a result, the communication channel is susceptible
to man-in-the-middle (MITM) attacks, where an attacker could intercept
or modify the transmitted data. Additionally, NeuVector loads the
response of the telemetry server is loaded into memory without size
limitation, which makes it vulnerable to a Denial of Service(DoS)
attack
In affected versions, NeuVector does not enforce TLS
certificate verification when transmitting anonymous cluster data to the
telemetry server. As a result, the communication channel is susceptible
to man-in-the-middle (MITM) attacks, where an attacker could intercept
or modify the transmitted data. Additionally, NeuVector loads the
response of the telemetry server is loaded into memory without size
limitation, which makes it vulnerable to a Denial of Service(DoS)
attack
AI Analysis
NeuVector is vulnerable to man-in-the-middle (MITM) attacks and Denial of Service (DoS) attacks due to lack of TLS certificate verification and unlimited loading of telemetry server responses.
Basic Information
ID
CVE-2025-54470
Source
suse
Published
Oct 30, 2025 at 09:38
Modified
Oct 30, 2025 at 14:01
Affected Product
Vendor
SUSE
Product
neuvector
Version
5.3.0
Affected Versions
SUSE neuvector 5.3.0
SUSE neuvector 5.4.0
SUSE neuvector 0.0.0-20230727023453-1c4957d53911
SUSE neuvector 5.4.0
SUSE neuvector 0.0.0-20230727023453-1c4957d53911
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
SUSE
Product
NeuVector
Version
5.3.0, 5.4.0