CVE 8.6 HIGH

NeuVector telemetry sender is vulnerable to MITM and DoS_CVE-2025-54470

8.6 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Description

This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVector sends anonymous telemetry data to the telemetry server.


In affected versions, NeuVector does not enforce TLS
certificate verification when transmitting anonymous cluster data to the
telemetry server. As a result, the communication channel is susceptible
to man-in-the-middle (MITM) attacks, where an attacker could intercept
or modify the transmitted data. Additionally, NeuVector loads the
response of the telemetry server is loaded into memory without size
limitation, which makes it vulnerable to a Denial of Service(DoS)
attack

AI Analysis

NeuVector is vulnerable to man-in-the-middle (MITM) attacks and Denial of Service (DoS) attacks due to lack of TLS certificate verification and unlimited loading of telemetry server responses.

Basic Information

ID CVE-2025-54470
Source suse
Published Oct 30, 2025 at 09:38
Modified Oct 30, 2025 at 14:01

Affected Product

Vendor SUSE
Product neuvector
Version 5.3.0
Affected Versions SUSE neuvector 5.3.0
SUSE neuvector 5.4.0
SUSE neuvector 0.0.0-20230727023453-1c4957d53911

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor SUSE
Product NeuVector
Version 5.3.0, 5.4.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.