« Volver al listado

CVE-2025-54467

Estado: AplazadaMedia (5.3)—

When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVector security event log.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-54467",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-54467",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-09-17T13:19:50.489206Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "meissner@suse.de",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "meissner@suse.de",
      "affectedData": [
        {
          "vendor": "SUSE",
          "product": "neuvector",
          "versions": [
            {
              "status": "affected",
              "version": "5.0.0",
              "lessThan": "5.4.6",
              "versionType": "semver"
            }
          ],
          "packageName": "github.com/neuvector/neuvector",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-09-17T13:15:34.017",
  "references": [
    {
      "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-54467",
      "source": "meissner@suse.de"
    },
    {
      "url": "https://github.com/neuvector/neuvector/security/advisories/GHSA-w54x-xfxg-4gxq",
      "source": "meissner@suse.de"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "meissner@suse.de",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVector security event log."
    },
    {
      "lang": "es",
      "value": "Cuando NeuVector ejecuta y finaliza un comando Java con parámetros de contraseña por NeuVector por violación de regla de proceso, la contraseña aparecerá en el registro de eventos de seguridad de NeuVector."
    }
  ],
  "lastModified": "2026-06-17T09:40:09.260",
  "sourceIdentifier": "meissner@suse.de"
}