Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-54470

Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-295 Validación incorrecta de certificados
Fecha de publicación:
30/10/2025
Última modificación:
30/10/2025

Descripción

*** Pendiente de traducción *** This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVector sends anonymous telemetry data to the telemetry server.<br /> <br /> <br /> In affected versions, NeuVector does not enforce TLS <br /> certificate verification when transmitting anonymous cluster data to the<br /> telemetry server. As a result, the communication channel is susceptible<br /> to man-in-the-middle (MITM) attacks, where an attacker could intercept <br /> or modify the transmitted data. Additionally, NeuVector loads the <br /> response of the telemetry server is loaded into memory without size <br /> limitation, which makes it vulnerable to a Denial of Service(DoS) <br /> attack