8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.
AI Analysis
NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM) attacks due to lack of TLS verification
Basic Information
ID
CVE-2025-66001
Source
suse
Published
Jan 8, 2026 at 10:23
Affected Product
Vendor
SUSE
Product
neuvector
Version
5.3.0
Affected Versions
SUSE neuvector 5.3.0
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
SUSE
Product
NeuVector
Version
5.3.0