VDB

CISA-2025-66001

CISA-2025-66001 PUBLISHED CVSS 8.8 HIGH

Reported by suse · Published January 8, 2026

NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.

Risk Scores

CVSS 3.1
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
SUSEneuvector5.3.0
SUSEneuvector5.3.0, 5.3.0

Timeline

  • Jan 8, 2026 CVE Published
  • Jan 8, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›