CVE-2025-54470
Severity CVSS v4.0:
Pending analysis
Type:
CWE-295
Improper Certificate Validation
Publication date:
30/10/2025
Last modified:
15/04/2026
Description
This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVector sends anonymous telemetry data to the telemetry server.<br />
<br />
<br />
In affected versions, NeuVector does not enforce TLS <br />
certificate verification when transmitting anonymous cluster data to the<br />
telemetry server. As a result, the communication channel is susceptible<br />
to man-in-the-middle (MITM) attacks, where an attacker could intercept <br />
or modify the transmitted data. Additionally, NeuVector loads the <br />
response of the telemetry server is loaded into memory without size <br />
limitation, which makes it vulnerable to a Denial of Service(DoS) <br />
attack
Impact
Base Score 3.x
8.60
Severity 3.x
HIGH



