CVE-2025-54470

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
30/10/2025
Last modified:
15/04/2026

Description

This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVector sends anonymous telemetry data to the telemetry server.<br /> <br /> <br /> In affected versions, NeuVector does not enforce TLS <br /> certificate verification when transmitting anonymous cluster data to the<br /> telemetry server. As a result, the communication channel is susceptible<br /> to man-in-the-middle (MITM) attacks, where an attacker could intercept <br /> or modify the transmitted data. Additionally, NeuVector loads the <br /> response of the telemetry server is loaded into memory without size <br /> limitation, which makes it vulnerable to a Denial of Service(DoS) <br /> attack