« Volver al listado

CVE-2025-54471

Estado: AplazadaMedia (6.5)—

NeuVector used a hard-coded cryptographic key embedded in the source code. At compilation time, the key value was replaced with the secret key value and used to encrypt sensitive configurations when NeuVector stores the data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-54471",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-54471",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-10-30T13:59:48.001541Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "meissner@suse.de",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "meissner@suse.de",
      "affectedData": [
        {
          "vendor": "SUSE",
          "product": "neuvector",
          "versions": [
            {
              "status": "affected",
              "version": "5.3.0",
              "lessThan": "5.4.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0.0.0-20230727023453-1c4957d53911",
              "lessThan": "0.0.0-20251020133207-084a437033b4",
              "versionType": "semver"
            }
          ],
          "packageName": "github.com/neuvector/neuvector",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-10-30T10:15:35.400",
  "references": [
    {
      "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-54471",
      "source": "meissner@suse.de"
    },
    {
      "url": "https://github.com/neuvector/neuvector/security/advisories/GHSA-h773-7gf7-9m2x",
      "source": "meissner@suse.de"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "meissner@suse.de",
      "description": [
        {
          "lang": "en",
          "value": "CWE-321"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NeuVector used a hard-coded cryptographic key embedded in the source \ncode. At compilation time, the key value was replaced with the secret \nkey value and used to encrypt sensitive configurations  when NeuVector \nstores the data."
    }
  ],
  "lastModified": "2026-06-17T09:40:09.693",
  "sourceIdentifier": "meissner@suse.de"
}