PT-2026-7954 · Neuvector · Neuvector

CVE-2025-67860

·

Publicado

2026-02-12

·

Atualizado

2026-03-03

CVSS v3.1

3.8

Baixa

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions NeuVector versions prior to 4.072
Description The NeuVector scanner insecurely handles passwords as command arguments. The scanner process accepts registry and controller credentials as command-line arguments, potentially exposing sensitive credentials to local users. This could allow unauthorized access to registries or the NeuVector controller, potentially enabling image manipulation, information disclosure, or further lateral movement within the environment. The impact severity for confidentiality, integrity and availability is dependent on the permissions the leaked credentials have on their services.
Recommendations Upgrade to NeuVector scanner version 4.072 or later.

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-67860
GHSA-3C9M-GQ32-G4JX
GO-2026-4490
SUSE-SU-2026:0757-1

Produtos afetados

Neuvector