CVE-2025-54470

8.6

SUSE · NeuVector

NeuVector fails to validate TLS certificates during telemetry transmission, enabling man-in-the-middle attacks and memory-based denial of service.

Executive summary

NeuVector deployments with anonymous cluster data reporting enabled are vulnerable to man-in-the-middle interception and denial-of-service attacks due to improper certificate validation.

Vulnerability

This is a man-in-the-middle and denial-of-service vulnerability caused by improper TLS certificate validation (CWE-295) and unbounded memory allocation during telemetry server communication. The vulnerability is exploitable by an unauthenticated attacker with network access to the telemetry path.

Business impact

The CVSS score of 8.6 indicates a high-severity risk. A successful exploit could allow an attacker to intercept or modify sensitive cluster telemetry data or crash the service through a memory-exhaustion denial-of-service attack, leading to potential loss of visibility and service downtime.

Remediation

Immediate Action: Upgrade to the patched versions provided by the vendor (specifically 5.3.5, 5.4.7, or the identified development build). If an immediate update is not feasible, disable the Report anonymous cluster data option in the NeuVector settings.

Proactive Monitoring: Monitor telemetry traffic logs for unauthorized intercept attempts or connection anomalies. Review system memory usage metrics to detect potential spikes associated with malicious telemetry server responses.

Compensating Controls: Utilize network segmentation to restrict access to the telemetry server endpoint. Implement a Web Application Firewall or egress filtering to inspect and restrict traffic to known-good telemetry destinations.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the potential for both data interception and service disruption, administrators should prioritize patching their NeuVector installations. If patching cannot be performed immediately, the configuration change to disable anonymous cluster reporting should be applied as a mandatory temporary control to eliminate the attack surface.

More SUSE CVEs

Sources