PT-2025-35110 · Neuvector · Neuvector

Binx-Suse

·

Publicado

2025-08-28

·

Atualizado

2025-09-22

·

CVE-2025-53884

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: NeuVector versions 5.0.0 through 5.4.5
Description: NeuVector stores user passwords and API keys using a simple, unsalted hash, making it vulnerable to rainbow table attacks. The software generates a cryptographically secure, random 16-character salt and uses it with the PBKDF2 algorithm when creating a user, updating a user’s password, or creating an API key. After upgrading to NeuVector 5.4.6, users must log in again to regenerate the password hash, and at least one request per API key must be sent to regenerate its hash value.
Recommendations: Upgrade to NeuVector version 5.4.6 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-53884
GHSA-8FF6-PC43-JWV3
GO-2025-3917
OPENSUSE-SU-2025:15538-1
SUSE-SU-2025:03289-1

Produtos afetados

Neuvector