---
cve: "CVE-2025-54470"
severity: "HIGH"
cvss: 8.6
epss: "18%"
vendor: "SUSE"
kev: false
exploited: false
published: "2025-10-30 10:15:35"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-05T21:24:13+02:00"
---

# CVE-2025-54470

> 8.6 HIGH · 🧪 PoC

## Beschreibung

This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVector sends anonymous telemetry data to the telemetry server.


In affected versions, NeuVector does not enforce TLS 
certificate verification when transmitting anonymous cluster data to the
 telemetry server. As a result, the communication channel is susceptible
 to man-in-the-middle (MITM) attacks, where an attacker could intercept 
or modify the transmitted data. Additionally, NeuVector loads the 
response of the telemetry server is loaded into memory without size 
limitation, which makes  it vulnerable to a Denial of Service(DoS) 
attack

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- b0e3a4eccf8b47a9b5c34c38a7d99442412a9500 (Commit)
- 06424701e69bf1eb76ff90180d78853fded93021 (Commit)

## Referenzen

- <https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-54470>
- <https://github.com/neuvector/neuvector/security/advisories/GHSA-qqj3-g7mx-5p4w>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-54470) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
